msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5x5g-h9x8-2fh9 msgpack5: Many buffered values can exhaust the streaming decoder stack
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.
Title msgpack5: Many buffered values can exhaust the streaming decoder stack
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:52:48.010Z

Reserved: 2026-10-07T15:53:23.587Z

Link: CVE-2026-107300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T17:17:16.000

Modified: 2026-10-08T18:17:17.697

Link: CVE-2026-107300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses