Impact
msgpack5 is a MessagePack v5 implementation for Node.js and browsers. Before version 6.1.0 the streaming decoder calls itself recursively for each complete value within a received chunk. A remote peer can craft a single chunk containing many small valid values, causing the recursion depth to grow linearly with the value count and eventually exhausting the JavaScript call stack. The result is a process or stream interruption, effectively denying service to the application.
Affected Systems
The vulnerability affects all installations of the msgpack5 library released by user mcollina before the 6.1.0 release. Any Node.js or browser application that uses msgpack5 5.x or 6.0.x and processes untrusted data streams is impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS is currently not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote peer that can send a crafted data chunk to the application’s msgpack decoder. If the attacker can send such a chunk, the recursion will consume the call stack and cause a denial‑of‑service. The lack of an immediate exploit in existing public exploits suggests the risk is primarily the inherent denial‑of‑service potential.
OpenCVE Enrichment
Github GHSA