Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.7 Node.js & npm GHSA-24ch-f2g6-9hhh CVE-2026-107298

msgpack5: deeply nested MessagePack can exhaust decoder stack (CVE-2026-107298)

msgpack5's array and map decoding have no nesting-depth limit prior to 6.1.0, allowing deeply nested MessagePack input to exhaust the JavaScript call stack and interrupt a process or request handler. (CVE-2026-107298) [4121, 31826]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

This advisory covers CVE-2026-107298 in the msgpack5 package. The issue lets crafted MessagePack data with deep nesting exhaust the JavaScript call stack during decoding, causing interruptions to processes, workers, or request handlers. A fix is available. [4121, 31826]

What happened

msgpack5's array and map decoding paths lacked a nesting-depth limit prior to the fixed release. Feeding deeply nested MessagePack containers to the decoder can exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This behaviour is documented in the advisory for CVE-2026-107298. [4121, 31826]

Technical cause

The decoder's array and map decoding implementation did not enforce a maximum container nesting depth, allowing unbounded recursion or stack usage when processing deeply nested containers. The advisory identifies this absence of a nesting-depth limit as the root cause. [4121]

Why it matters

Successful exploitation can interrupt application availability by exhausting the JavaScript call stack during decoding. The issue has a CVSS v3.1 base score of 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L), indicating a network-reachable denial-of-service impact. Patchwire's computed score for prioritization is 3.7, which incorporates that the flaw is remotely reachable without authentication and requires no user interaction. [31826, 4121]

Who is affected

Projects and applications that include the msgpack5 npm package for MessagePack v5 decoding in Node.js or the browser and that use a release prior to the fixed release are affected. The package advisory reports the affected range as introduced at 0 and fixed in 6.1.0. [4121]

Discovery and timeline

The vulnerability was published in the referenced advisories on 2026-10-08 (OSV.dev entry) and is recorded in the NVD entry for CVE-2026-107298. The advisory metadata shows publication dates in those sources. [4121, 31826]

Affected versions

The advisory describes the affected range as introduced at version 0 and fixed in version 6.1.0. Versions prior to 6.1.0 are therefore within the affected range. [4121]

Fixes and mitigation

A fix is available. The advisory and package metadata list version 6.1.0 as the fixed release for msgpack5. [4121]

Recommended action

Upgrade any deployments that use msgpack5 to the fixed release (6.1.0) as provided in the advisory. Confirm that your dependency updates include the msgpack5 change before deploying. [4121]

PatchBriefing score

3.7 / 10 · Low

Official CVSS: 5.3

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Why this score

The advisory reports a CVSS v3.1 base score of 5.3 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L), reflecting a network-accessible denial-of-service impact with no confidentiality or integrity loss. Patchwire's prioritization score is 3.7; its contributing factors include the CVSS base (5.3), that the flaw is remotely reachable without authentication, and that no user interaction is required. Public exploit and known-exploited flags are false in the advisory. [31826, 4121]

Affected versions

msgpack5 ≥ 0 < 6.1.0
vulnerable
≥ 6.1.0
patched

Reported fixes

A fix is available. The advisory and package metadata list version 6.1.0 as the fixed release for msgpack5. [4121]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
msgpack5: deeply nested MessagePack can exhaust decoder stack (CVE-2026-107298)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email