Medium · 4.9 Node.js & npm GHSA-5x5g-h9x8-2fh9 CVE-2026-107300
msgpack5: streaming decoder stack exhaustion (CVE-2026-107300)
A flaw in msgpack5's streaming decoder can exhaust the JavaScript call stack when a single chunk contains many small MessagePack values; the issue is fixed in 6.1.0. (CVE-2026-107300)
AI summary
CVE-2026-107300 affects the msgpack5 library used in Node.js and browser contexts. A streaming-decoder implementation can recurse for each MessagePack value in a chunk; an input with many small values may exhaust the JavaScript call stack and interrupt the process or stream. A vendor fix is available in 6.1.0.
What happened
msgpack5's streaming decoder recursively invokes itself for each complete MessagePack value remaining in a received chunk. A remote peer can send a single chunk containing many small valid values; because the decoder recurses proportional to the value count this can exhaust the JavaScript call stack and interrupt the process or stream. This behaviour is described in the advisory for CVE-2026-107300. (Sources: OSV and NVD.)
Technical cause
The streaming decoder's implementation repeatedly invokes the decoder routine for every remaining complete value in a chunk rather than iterating without growing the call stack. When a chunk contains many small values, recursion depth grows with the number of values and can exceed the JavaScript call stack limit, causing a crash or stream interruption.
Why it matters
The issue has CVSS 3.1 base score 7.5 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating a high impact on availability without confidentiality or integrity loss. Patchwire's composite score for this advisory is 4.9; factor contributions include the CVSS base score (4.13), the fact that the vulnerability can be triggered remotely without authentication (0.6), and that no user interaction is required (0.2). There are no public exploit reports and no known exploitation in the wild per the sources.
Who is affected
Applications that depend on the msgpack5 package (used in Node.js and browser environments) and accept MessagePack-encoded chunks from remote peers are affected when running a vulnerable release. The advisory identifies msgpack5 as the affected product.
Discovery and timeline
The vulnerability is recorded in OSV and NVD. OSV published an advisory titled “msgpack5: Many buffered values can exhaust the streaming decoder stack” on 2026-10-08; NVD lists CVE-2026-107300 with publication metadata. (See the source entries for timestamps and records.)
Affected versions
The advisory states the issue is present from version 0 and is fixed in version 6.1.0. In other words, releases introduced at 0 and prior to 6.1.0 are affected; the fix is present in 6.1.0.
Fixes and mitigation
A fix is available in msgpack5 version 6.1.0 according to the advisory. The sources do not provide alternate mitigation steps beyond applying the vendor update.
Recommended action
Upgrade affected deployments to msgpack5 version 6.1.0. Test the update in your environment and deploy it according to your change-control practices. If you cannot immediately upgrade, review your exposure to untrusted MessagePack input and restrict or validate inputs where possible; the advisory itself provides the versioned fix as the primary remediation.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates a high availability impact without confidentiality or integrity loss. Patchwire score 4.9 reflects the CVSS contribution plus the fact this can be triggered remotely without authentication and requires no user interaction; the advisory reports no public exploit and no known exploitation in the wild.
Affected versions
- msgpack5 ≥ 0 < 6.1.0
- vulnerable
- ≥ 6.1.0
- patched
Reported fixes
A fix is available in msgpack5 version 6.1.0 according to the advisory. The sources do not provide alternate mitigation steps beyond applying the vendor update.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email