Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-5x5g-h9x8-2fh9 CVE-2026-107300

msgpack5: streaming decoder stack exhaustion (CVE-2026-107300)

A flaw in msgpack5's streaming decoder can exhaust the JavaScript call stack when a single chunk contains many small MessagePack values; the issue is fixed in 6.1.0. (CVE-2026-107300)

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

CVE-2026-107300 affects the msgpack5 library used in Node.js and browser contexts. A streaming-decoder implementation can recurse for each MessagePack value in a chunk; an input with many small values may exhaust the JavaScript call stack and interrupt the process or stream. A vendor fix is available in 6.1.0.

What happened

msgpack5's streaming decoder recursively invokes itself for each complete MessagePack value remaining in a received chunk. A remote peer can send a single chunk containing many small valid values; because the decoder recurses proportional to the value count this can exhaust the JavaScript call stack and interrupt the process or stream. This behaviour is described in the advisory for CVE-2026-107300. (Sources: OSV and NVD.)

Technical cause

The streaming decoder's implementation repeatedly invokes the decoder routine for every remaining complete value in a chunk rather than iterating without growing the call stack. When a chunk contains many small values, recursion depth grows with the number of values and can exceed the JavaScript call stack limit, causing a crash or stream interruption.

Why it matters

The issue has CVSS 3.1 base score 7.5 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating a high impact on availability without confidentiality or integrity loss. Patchwire's composite score for this advisory is 4.9; factor contributions include the CVSS base score (4.13), the fact that the vulnerability can be triggered remotely without authentication (0.6), and that no user interaction is required (0.2). There are no public exploit reports and no known exploitation in the wild per the sources.

Who is affected

Applications that depend on the msgpack5 package (used in Node.js and browser environments) and accept MessagePack-encoded chunks from remote peers are affected when running a vulnerable release. The advisory identifies msgpack5 as the affected product.

Discovery and timeline

The vulnerability is recorded in OSV and NVD. OSV published an advisory titled “msgpack5: Many buffered values can exhaust the streaming decoder stack” on 2026-10-08; NVD lists CVE-2026-107300 with publication metadata. (See the source entries for timestamps and records.)

Affected versions

The advisory states the issue is present from version 0 and is fixed in version 6.1.0. In other words, releases introduced at 0 and prior to 6.1.0 are affected; the fix is present in 6.1.0.

Fixes and mitigation

A fix is available in msgpack5 version 6.1.0 according to the advisory. The sources do not provide alternate mitigation steps beyond applying the vendor update.

Recommended action

Upgrade affected deployments to msgpack5 version 6.1.0. Test the update in your environment and deploy it according to your change-control practices. If you cannot immediately upgrade, review your exposure to untrusted MessagePack input and restrict or validate inputs where possible; the advisory itself provides the versioned fix as the primary remediation.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

CVSS 3.1 base score 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates a high availability impact without confidentiality or integrity loss. Patchwire score 4.9 reflects the CVSS contribution plus the fact this can be triggered remotely without authentication and requires no user interaction; the advisory reports no public exploit and no known exploitation in the wild.

Affected versions

msgpack5 ≥ 0 < 6.1.0
vulnerable
≥ 6.1.0
patched

Reported fixes

A fix is available in msgpack5 version 6.1.0 according to the advisory. The sources do not provide alternate mitigation steps beyond applying the vendor update.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
msgpack5: streaming decoder stack exhaustion (CVE-2026-107300)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email