Impact
The vulnerability is in msgpack5, a MessagePack implementation for Node.js and browsers. Prior to version 6.1.0 the streaming decoder mistakenly treats the reserved MessagePack byte 0xc1 as incomplete input rather than invalid. When a stream begins with 0xc1, the decoder buffers subsequent data, waiting for bytes that can never produce a valid value. This behavior enables a remote peer to send a crafted stream that causes the application to allocate unbounded memory, resulting in a denial of service. The weakness is identified as CWE-228 and is measurable by a CVSS score of 5.9.
Affected Systems
The affected product is msgpack5 released by mcollina. Versions earlier than 6.1.0 are impacted. The fix was introduced in release 6.1.0 and later versions are not vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network for applications that accept user input through msgpack5 streaming. An attacker can trigger memory exhaustion by sending a stream that starts with 0xc1 and then continues with data that prevents the decoder from completing the value. The impact is a denial of service that can bring down the target application if not mitigated.
OpenCVE Enrichment
Github GHSA