Impact
msgpack5 is a MessagePack v5 implementation for Node.js and browser environments. The vulnerability resides in its streaming decoder, which re‑parses an incomplete array or map from the beginning each time a new chunk arrives. A well‑intentioned or malicious remote party can split one valid MessagePack container into many tiny fragments, causing the decoder to repeatedly process finished elements. The repeated work creates a quadratic growth in CPU usage and can block the event loop, making the application unresponsive. This flaw is a classic case of inefficient algorithm use (CWE‑407).
Affected Systems
The weakness affects the mcollina:msgpack5 library distributed to Node.js and browser JavaScript applications. All versions before 6.1.0 are vulnerable. The issue is resolved in v6.1.0, so any deployment using an earlier release and exposing the streaming decoder to untrusted input is at risk.
Risk and Exploitability
The CVSS score of 5.9 rates the flaw as moderate; it is not listed in the CISA KEV catalog and no EPSS data is available. The flaw is remotely exploitable over the network because a client can craft message fragments that trigger excessive CPU cycles. An attacker who can cause the target to repeatedly re‑parse data could exhaust CPU resources and force a denial of service. The lack of a higher exploitation score implies the threat may be moderate in likelihood, but the potential impact on service availability makes mitigation important.
OpenCVE Enrichment
Github GHSA