Medium · 4.0 Node.js & npm GHSA-26wq-p25c-j6fv CVE-2026-107299
CVE-2026-107299 — msgpack5 reserved byte can cause unbounded stream buffering
msgpack5's streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input, allowing a remote peer to cause unbounded buffering and possible memory exhaustion. A fix is available in 6.1.0. [sources: 4127, 31827]
AI summary
CVE-2026-107299 (GHSA-26wq-p25c-j6fv) affects msgpack5, a MessagePack v5 implementation for Node.js and browser environments. The streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input rather than invalid, which can leave subsequent data buffered and permit a remote peer to exhaust memory. The issue is fixed in version 6.1.0. [sources: 4127, 31827]
What happened
The streaming decoder in msgpack5 treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When a stream begins with 0xc1, the decoder waits for bytes that cannot make the value valid and leaves subsequent data buffered, allowing a remote peer to cause unbounded buffering and exhaust memory. [sources: 4127, 31827]
Technical cause
The decoder's stream handling logic misclassifies the reserved 0xc1 byte as 'incomplete' rather than an invalid value, so it continues to buffer input while awaiting bytes that cannot produce a valid value. The advisory lists the underlying weakness as CWE-228. [sources: 4127, 31827]
Why it matters
Buffered data can grow without bound when a remote peer begins a stream with 0xc1, enabling memory exhaustion on the decoding side. The advisory notes the issue is reachable from unauthenticated remote inputs and requires no user interaction. [sources: 4127, 31827]
Who is affected
Applications and services that use the msgpack5 library (npm) for MessagePack v5 streaming decoding are affected. [sources: 4127, 31827]
Discovery and timeline
The advisory was published to OSV.dev on 2026-10-08T17:40:01+02:00 and appears in the NVD entry published 2026-10-08T17:17:15+02:00; the advisory record was modified 2026-10-09T16:17:22+02:00. Source records: OSV.dev and NVD. [sources: 4127, 31827]
Affected versions
The package msgpack5 is affected from version 0 up to, but not including, 6.1.0. The vendor provides a fix in 6.1.0. [sources: 4127, 31827]
Fixes and mitigation
A fix is available; the advisory and package claims list 6.1.0 as the fixed version for msgpack5. The advisory marks "fix_available" as true. No other mitigations or workarounds are documented in the provided facts. [sources: 4127, 31827]
Recommended action
Update msgpack5 to the fixed release 6.1.0. The provided facts do not document alternative vendor workarounds; if you cannot update, note that no workaround is listed in the supplied advisory information. [sources: 4127, 31827]
PatchBriefing score
4.0 / 10 · Medium
Official CVSS: 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
This issue has a CVSS v3.1 base score of 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H). The advisory's PatchWire score is 4. Contributing factors in the advisory data include the CVSS base score and that the issue is reachable from unauthenticated remote input and requires no user interaction; the data shows no known public exploit and a fix is available. [sources: 4127, 31827]
Affected versions
- msgpack5 ≥ 0 < 6.1.0
- vulnerable
- ≥ 6.1.0
- patched
Reported fixes
A fix is available; the advisory and package claims list 6.1.0 as the fixed version for msgpack5. The advisory marks "fix_available" as true. No other mitigations or workarounds are documented in the provided facts. [sources: 4127, 31827]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email