Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

msgpack5 is a MessagePack v5 implementation for Node.js and browsers. Before version 6.1.0 the streaming decoder calls itself recursively for each complete value within a received chunk. A remote peer can craft a single chunk containing many small valid values, causing the recursion depth to grow linearly with the value count and eventually exhausting the JavaScript call stack. The result is a process or stream interruption, effectively denying service to the application.

Affected Systems

The vulnerability affects all installations of the msgpack5 library released by user mcollina before the 6.1.0 release. Any Node.js or browser application that uses msgpack5 5.x or 6.0.x and processes untrusted data streams is impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. EPSS is currently not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote peer that can send a crafted data chunk to the application’s msgpack decoder. If the attacker can send such a chunk, the recursion will consume the call stack and cause a denial‑of‑service. The lack of an immediate exploit in existing public exploits suggests the risk is primarily the inherent denial‑of‑service potential.

Generated by OpenCVE AI on October 8, 2026 at 18:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade msgpack5 to version 6.1.0 or later
  • Validate incoming streams to enforce limits on chunk size or maximum value count before decoding
  • Monitor for repeated large‑chunk inputs and apply application‑level or network‑level filtering to mitigate denial‑of‑service attempts

Generated by OpenCVE AI on October 8, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5x5g-h9x8-2fh9 msgpack5: Many buffered values can exhaust the streaming decoder stack
History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.
Title msgpack5: Many buffered values can exhaust the streaming decoder stack
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:52:48.010Z

Reserved: 2026-10-07T15:53:23.587Z

Link: CVE-2026-107300

cve-icon Vulnrichment

Updated: 2026-10-08T17:52:42.623Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T17:17:16.000

Modified: 2026-10-08T20:48:36.970

Link: CVE-2026-107300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses