Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or worker in applications that wait for additional bytes after IncompleteBufferError. There is no adjacent-memory disclosure because the buffer implementation checks bounds. This issue is fixed in version 6.1.0.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

msgpack5 is a MessagePack v5 implementation used in Node.js and browser environments. In versions prior to 6.1.0, the decoder reads the four‑byte length of a map32 value before verifying that the entire five‑byte header is available. When a header is truncated, this leads to an out‑of‑bounds buffer read that throws a RangeError instead of the expected IncompleteBufferError. The unexpected exception can cause a request, stream, or worker to terminate, resulting in an availability impact without exposing adjacent memory.

Affected Systems

The vulnerable product is msgpack5, developed by mcollina. All releases before 6.1.0 are affected, including those used in Node.js backends and web front‑ends.

Risk and Exploitability

The CVSS score of 7.5 signals a high severity local availability disruption. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector involves an attacker supplying malformed input containing an incomplete map32 header to the decoder when the application accepts data from untrusted sources. The flaw does not permit code execution or data disclosure; the outcome is a denial‑of‑service via an unhandled RangeError.

Generated by OpenCVE AI on October 8, 2026 at 18:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade msgpack5 to v6.1.0 or later to apply the official fix.
  • If an upgrade cannot be applied immediately, validate that any incoming buffer includes a complete 5‑byte map32 header before calling the decoder; reject or skip incomplete messages.
  • Wrap decoder calls in a try/catch block to capture RangeError, log the issue, and terminate the request gracefully instead of letting the exception crash the application.

Generated by OpenCVE AI on October 8, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8f34-f56x-9xph msgpack5: Truncated map32 headers throw an unexpected error
History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or worker in applications that wait for additional bytes after IncompleteBufferError. There is no adjacent-memory disclosure because the buffer implementation checks bounds. This issue is fixed in version 6.1.0.
Title msgpack5: Truncated map32 headers throw an unexpected error
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:32:23.572Z

Reserved: 2026-10-07T15:53:23.587Z

Link: CVE-2026-107302

cve-icon Vulnrichment

Updated: 2026-10-08T17:32:19.946Z

cve-icon NVD

Status : Received

Published: 2026-10-08T18:17:19.100

Modified: 2026-10-08T18:17:19.100

Link: CVE-2026-107302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:00:07Z

Weaknesses