Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 2.8 Node.js & npm GHSA-qw35-55vc-rhgj CVE-2026-107296

msgpack5: Decoding negative int64 mutates input buffer (CVE-2026-107296)

msgpack5 updates to 6.1.0 fix an issue where decoding a negative signed 64-bit integer can overwrite bytes in the caller-provided input buffer, causing silent corruption of retained or reused encoded data. (CVE-2026-107296, GHSA-qw35-55vc-rhgj)

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A flaw in msgpack5 can cause decoding of negative signed 64-bit integers to modify the original input buffer used by the caller. The issue is tracked as CVE-2026-107296 / GHSA-qw35-55vc-rhgj and is fixed in 6.1.0. This briefing explains what is affected, why it matters, and recommended actions.

What happened

Decoding a negative signed 64-bit integer with msgpack5 modifies the corresponding bytes in the caller-supplied input buffer while computing the value. Positive integers and other MessagePack types are not affected. The behavior can lead to silent corruption of encoded data that applications retain or later reuse for integrity checks, logging, or processing.

Technical cause

The decoder's handling of negative signed 64-bit (int64) values performs in-place modification of the bytes in the provided input buffer during value computation. That mutation occurs only for negative signed 64-bit integers; other value types are unaffected.

Why it matters

Applications that retain or reuse the original encoded buffer — for example for integrity checks, logging, or later processing — can observe silently corrupted data after decoding negative int64 values. The published severity (CVSS 3.1 base score 3.7; vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N) reflects a low base impact limited to integrity.

Who is affected

Projects and applications that use the msgpack5 library to decode MessagePack data and that retain or later reuse the original encoded input buffer are at risk of observing corrupted bytes when negative signed 64-bit integers are decoded. Systems that neither retain nor reuse input buffers are not affected in their retained data.

Discovery and timeline

The issue is published in OSV and the NVD. OSV published an advisory titled "msgpack5: Decoding negative int64 values mutates the input buffer" on 2026-10-08; the NVD entry for CVE-2026-107296 is also available with its publication timestamp. The vulnerability record lists a fix event to 6.1.0.

Affected versions

The advisory reports the package msgpack5 is affected from introduced version "0" up to being fixed in "6.1.0".

Fixes and mitigation

A fix is available in msgpack5 version "6.1.0". Users should update to that version to receive the correction. If immediate updating is not possible, avoid retaining or reusing the original encoded input buffers after decoding, or re-serialize decoded values into a fresh buffer before any integrity checks or logging.

Recommended action

1) Update msgpack5 to "6.1.0". 2) Audit code paths that retain or reuse MessagePack input buffers; where buffers are retained, consider re-encoding or copying decoded data before downstream use. 3) Test systems that depend on retained encoded data for integrity checks or logging to ensure no silent corruption has previously occurred.

PatchBriefing score

2.8 / 10 · Low

Official CVSS: 3.7

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Why this score

The advisory provides a CVSS v3.1 base score of 3.7 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N), which corresponds to a low base severity driven by limited integrity impact. PatchWire's combined score for prioritization is 2.8; contributing factors include unauthenticated remote reachability and no required user interaction.

Affected versions

msgpack5 ≥ 0 < 6.1.0
vulnerable
≥ 6.1.0
patched

Reported fixes

A fix is available in msgpack5 version "6.1.0". Users should update to that version to receive the correction. If immediate updating is not possible, avoid retaining or reusing the original encoded input buffers after decoding, or re-serialize decoded values into a fresh buffer before any integrity checks or logging.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
msgpack5: Decoding negative int64 mutates input buffer (CVE-2026-107296)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email