Impact
msgpack5 is a MessagePack v5 implementation used in Node.js and browser environments. In versions prior to 6.1.0, the decoder reads the four‑byte length of a map32 value before verifying that the entire five‑byte header is available. When a header is truncated, this leads to an out‑of‑bounds buffer read that throws a RangeError instead of the expected IncompleteBufferError. The unexpected exception can cause a request, stream, or worker to terminate, resulting in an availability impact without exposing adjacent memory.
Affected Systems
The vulnerable product is msgpack5, developed by mcollina. All releases before 6.1.0 are affected, including those used in Node.js backends and web front‑ends.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity local availability disruption. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector involves an attacker supplying malformed input containing an incomplete map32 header to the decoder when the application accepts data from untrusted sources. The flaw does not permit code execution or data disclosure; the outcome is a denial‑of‑service via an unhandled RangeError.
OpenCVE Enrichment
Github GHSA