Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

msgpack5 is a MessagePack v5 implementation for Node.js and browser environments. The vulnerability resides in its streaming decoder, which re‑parses an incomplete array or map from the beginning each time a new chunk arrives. A well‑intentioned or malicious remote party can split one valid MessagePack container into many tiny fragments, causing the decoder to repeatedly process finished elements. The repeated work creates a quadratic growth in CPU usage and can block the event loop, making the application unresponsive. This flaw is a classic case of inefficient algorithm use (CWE‑407).

Affected Systems

The weakness affects the mcollina:msgpack5 library distributed to Node.js and browser JavaScript applications. All versions before 6.1.0 are vulnerable. The issue is resolved in v6.1.0, so any deployment using an earlier release and exposing the streaming decoder to untrusted input is at risk.

Risk and Exploitability

The CVSS score of 5.9 rates the flaw as moderate; it is not listed in the CISA KEV catalog and no EPSS data is available. The flaw is remotely exploitable over the network because a client can craft message fragments that trigger excessive CPU cycles. An attacker who can cause the target to repeatedly re‑parse data could exhaust CPU resources and force a denial of service. The lack of a higher exploitation score implies the threat may be moderate in likelihood, but the potential impact on service availability makes mitigation important.

Generated by OpenCVE AI on October 8, 2026 at 18:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade msgpack5 to version 6.1.0 or later, which replaces the streaming decoder with a fixed implementation.
  • If upgrading is not immediately possible, limit the size or number of message chunks consumed, or add input validation to reject excessively fragmented or large inputs.
  • Where feasible, monitor CPU utilization for the Node.js process and implement rate limiting or process isolation to contain the impact of any accidental recursion in the decoder.

Generated by OpenCVE AI on October 8, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gcx5-hxj7-gpqq msgpack5: Quadratic parsing in the streaming decoder
History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.
Title msgpack5: Quadratic parsing in the streaming decoder
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:26:27.457Z

Reserved: 2026-10-07T15:53:23.587Z

Link: CVE-2026-107297

cve-icon Vulnrichment

Updated: 2026-10-08T17:26:23.378Z

cve-icon NVD

Status : Received

Published: 2026-10-08T17:17:15.550

Modified: 2026-10-08T18:17:17.490

Link: CVE-2026-107297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity