Medium · 4.9 Node.js & npm GHSA-8f34-f56x-9xph CVE-2026-107302
CVE-2026-107302 — msgpack5: truncated map32 headers cause unexpected RangeError
msgpack5 decoders read the four-byte length of a map32 before confirming the full five-byte header is present. A truncated header can trigger a checked out-of-bounds read and throw RangeError instead of IncompleteBufferError, which may terminate requests, streams, or workers. Fixed in 6.1.0. (Sources: 4122, 31839)
AI summary
msgpack5, a MessagePack v5 implementation for Node.js and browsers, contains an input-handling bug where a truncated map32 header leads the decoder to throw RangeError instead of IncompleteBufferError. The behavior can unexpectedly terminate a request, stream, or worker. The issue is fixed in version 6.1.0. (Sources: 4122, 31839)
What happened
The msgpack5 decoder reads the four-byte length field of a map32 value before validating that the decoder has the full five-byte header available. If the header is truncated, the decoder performs a checked out-of-bounds buffer read and throws a RangeError instead of IncompleteBufferError. Because some applications treat IncompleteBufferError as a signal to wait for more bytes, the unexpected RangeError can terminate a request, stream, or worker. There is no adjacent-memory disclosure because the buffer implementation enforces bounds checks. (Sources: 4122, 31839)
Technical cause
The decoder's logic validates the four-byte length field for map32 before confirming the full five-byte header is present; a truncated header therefore leads to a checked out-of-bounds read that raises RangeError instead of the expected IncompleteBufferError. (Sources: 4122, 31839)
Why it matters
The observable impact is denial-of-service of an individual request, stream, or worker due to an unexpected exception (RangeError). Because confidentiality and integrity are not affected by the described bounds checks, the primary risk is availability interruption in applications that rely on IncompleteBufferError to signal incomplete input. (Sources: 4122, 31839)
Who is affected
Applications that use the msgpack5 package (Node.js or browser builds) to decode MessagePack data may be affected when they encounter a truncated map32 header. (Sources: 4122, 31839)
Discovery and timeline
The vulnerability is documented in OSV and the NVD. OSV entry published 2026-10-08T17:40:10+02:00; NVD entry published 2026-10-08T18:17:19+02:00. (Sources: 4122, 31839)
Affected versions
The advisory reports the affected range as introduced at 0 and fixed at 6.1.0. (Sources: 4122)
Fixes and mitigation
A fix is available: the issue is fixed in version 6.1.0 of msgpack5. (Sources: 4122)
Recommended action
Update msgpack5 to version 6.1.0. If you cannot upgrade immediately, review how your application handles decoder exceptions and avoid assuming IncompleteBufferError for all incomplete-input conditions; however, the provided advisory only documents the code fix and the published fixed version. (Sources: 4122, 31839)
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
CVSS v3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The vector indicates a network-accessible, low-complexity issue requiring no privileges or user interaction. The impact is limited to availability (A:H) rather than confidentiality or integrity. The computed PatchWire score factors this base severity and the fact that the issue is remotely triggerable without authentication. (Sources: 31839, 4122)
Affected versions
- msgpack5 ≥ 0 < 6.1.0
- vulnerable
- ≥ 6.1.0
- patched
Reported fixes
A fix is available: the issue is fixed in version 6.1.0 of msgpack5. (Sources: 4122)
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email