Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.
Published: 2026-10-08
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is in msgpack5, a MessagePack implementation for Node.js and browsers. Prior to version 6.1.0 the streaming decoder mistakenly treats the reserved MessagePack byte 0xc1 as incomplete input rather than invalid. When a stream begins with 0xc1, the decoder buffers subsequent data, waiting for bytes that can never produce a valid value. This behavior enables a remote peer to send a crafted stream that causes the application to allocate unbounded memory, resulting in a denial of service. The weakness is identified as CWE-228 and is measurable by a CVSS score of 5.9.

Affected Systems

The affected product is msgpack5 released by mcollina. Versions earlier than 6.1.0 are impacted. The fix was introduced in release 6.1.0 and later versions are not vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote network for applications that accept user input through msgpack5 streaming. An attacker can trigger memory exhaustion by sending a stream that starts with 0xc1 and then continues with data that prevents the decoder from completing the value. The impact is a denial of service that can bring down the target application if not mitigated.

Generated by OpenCVE AI on October 8, 2026 at 18:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade msgpack5 to version 6.1.0 or later
  • If an upgrade is not immediately possible, validate input streams to reject any that contain the reserved byte 0xc1 before they reach the decoder
  • Implement memory usage monitoring and set limits on buffer size to detect and prevent excessive consumption

Generated by OpenCVE AI on October 8, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-26wq-p25c-j6fv msgpack5: Reserved byte can cause unbounded stream buffering
History

Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.
Title msgpack5: Reserved byte can cause unbounded stream buffering
Weaknesses CWE-228
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:09:47.191Z

Reserved: 2026-10-07T15:53:23.587Z

Link: CVE-2026-107299

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T17:17:15.850

Modified: 2026-10-08T20:48:36.970

Link: CVE-2026-107299

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses
  • CWE-228

    Improper Handling of Syntactically Invalid Structure