Low · 3.7 Node.js & npm GHSA-24ch-f2g6-9hhh CVE-2026-107298
msgpack5: deeply nested MessagePack can exhaust decoder stack (CVE-2026-107298)
msgpack5's array and map decoding have no nesting-depth limit prior to 6.1.0, allowing deeply nested MessagePack input to exhaust the JavaScript call stack and interrupt a process or request handler. (CVE-2026-107298) [4121, 31826]
AI summary
This advisory covers CVE-2026-107298 in the msgpack5 package. The issue lets crafted MessagePack data with deep nesting exhaust the JavaScript call stack during decoding, causing interruptions to processes, workers, or request handlers. A fix is available. [4121, 31826]
What happened
msgpack5's array and map decoding paths lacked a nesting-depth limit prior to the fixed release. Feeding deeply nested MessagePack containers to the decoder can exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This behaviour is documented in the advisory for CVE-2026-107298. [4121, 31826]
Technical cause
The decoder's array and map decoding implementation did not enforce a maximum container nesting depth, allowing unbounded recursion or stack usage when processing deeply nested containers. The advisory identifies this absence of a nesting-depth limit as the root cause. [4121]
Why it matters
Successful exploitation can interrupt application availability by exhausting the JavaScript call stack during decoding. The issue has a CVSS v3.1 base score of 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L), indicating a network-reachable denial-of-service impact. Patchwire's computed score for prioritization is 3.7, which incorporates that the flaw is remotely reachable without authentication and requires no user interaction. [31826, 4121]
Who is affected
Projects and applications that include the msgpack5 npm package for MessagePack v5 decoding in Node.js or the browser and that use a release prior to the fixed release are affected. The package advisory reports the affected range as introduced at 0 and fixed in 6.1.0. [4121]
Discovery and timeline
The vulnerability was published in the referenced advisories on 2026-10-08 (OSV.dev entry) and is recorded in the NVD entry for CVE-2026-107298. The advisory metadata shows publication dates in those sources. [4121, 31826]
Affected versions
The advisory describes the affected range as introduced at version 0 and fixed in version 6.1.0. Versions prior to 6.1.0 are therefore within the affected range. [4121]
Fixes and mitigation
A fix is available. The advisory and package metadata list version 6.1.0 as the fixed release for msgpack5. [4121]
Recommended action
Upgrade any deployments that use msgpack5 to the fixed release (6.1.0) as provided in the advisory. Confirm that your dependency updates include the msgpack5 change before deploying. [4121]
PatchBriefing score
3.7 / 10 · Low
Official CVSS: 5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Why this score
The advisory reports a CVSS v3.1 base score of 5.3 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L), reflecting a network-accessible denial-of-service impact with no confidentiality or integrity loss. Patchwire's prioritization score is 3.7; its contributing factors include the CVSS base (5.3), that the flaw is remotely reachable without authentication, and that no user interaction is required. Public exploit and known-exploited flags are false in the advisory. [31826, 4121]
Affected versions
- msgpack5 ≥ 0 < 6.1.0
- vulnerable
- ≥ 6.1.0
- patched
Reported fixes
A fix is available. The advisory and package metadata list version 6.1.0 as the fixed release for msgpack5. [4121]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email