Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.0 Node.js & npm GHSA-gcx5-hxj7-gpqq CVE-2026-107297

msgpack5: Quadratic parsing in streaming decoder (CVE-2026-107297)

A flaw in msgpack5's streaming decoder causes repeated reparsing of completed elements when a MessagePack container is split across chunks, allowing a remote peer to induce quadratic CPU usage and block the Node.js event loop. Fixed in 6.1.0. (CVE-2026-107297)

Synthesized by AI from 2 sources · updated 2 hours ago

AI summary

The msgpack5 npm package contains a flaw in its streaming decoder that can be triggered by splitting a single MessagePack container across many small chunks. This causes completed elements to be decoded repeatedly, producing quadratic CPU usage and potentially blocking the Node.js event loop. A fix is available in 6.1.0. (Sources: OSV, NVD.)

What happened

The streaming decoder in msgpack5 reparses an incomplete array or map from the beginning whenever another chunk arrives. If a remote peer splits one valid MessagePack container across many small chunks, completed elements can be decoded repeatedly, producing quadratic CPU use and blocking the event loop. (Sources: 4124, 31825)

Technical cause

The decoder's streaming logic restarts parsing of an incomplete array or map from the start each time a new chunk is appended, rather than resuming at the correct state. That behavior leads to repeated work as data accumulates across chunks, creating quadratic CPU complexity for specially crafted chunking patterns. (Sources: 4124, 31825)

Why it matters

An unauthenticated remote peer can cause high CPU consumption and event-loop blocking by sending a valid MessagePack container split into many small chunks. The CVSS vector indicates an availability impact only (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) and the computed CVSS base score is 5.9. There are no public exploit reports noted in the sources. (Sources: 4124, 31825)

Who is affected

The npm package msgpack5 is affected. The vulnerability is present in releases introduced at 0 and fixed in 6.1.0; builds that use any release prior to 6.1.0 are affected. Whether an application is exposed depends on whether it decodes MessagePack streams from untrusted or remote peers. (Sources: 4124, 31825)

Discovery and timeline

The issue is published in the OSV entry and NVD record referenced below. OSV published the advisory on 2026-10-08. (Sources: 4124, 31825)

Affected versions

The advisory identifies releases introduced at 0 and fixed in 6.1.0. In other words, releases prior to 6.1.0 are affected; the fix is present in 6.1.0. (Sources: 4124, 31825)

Fixes and mitigation

A vendor update that fixes the streaming decoder logic is available in 6.1.0. The advisory indicates the issue is fixed in that release. No alternate mitigations (such as configuration changes or patches) are documented in the provided sources. (Sources: 4124, 31825)

Recommended action

Update msgpack5 to 6.1.0. If you cannot update immediately, restrict or validate MessagePack input from untrusted or remote peers where possible and monitor event-loop latency and CPU usage in services that decode MessagePack streams. The sources do not list public exploits or proof-of-concept code. (Sources: 4124, 31825)

PatchBriefing score

4.0 / 10 · Medium

Official CVSS: 5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

PatchWire score: 4. Computation factors include the CVSS base score of 5.9 (contribution 3.25), unauthenticated remote attack capability (contribution 0.6), and no user interaction required (contribution 0.2). There are no known exploits or public exploit reports in the sources; that contributed 0 to the score. (Sources: 4124, 31825)

Affected versions

msgpack5 ≥ 0 < 6.1.0
vulnerable
≥ 6.1.0
patched

Reported fixes

A vendor update that fixes the streaming decoder logic is available in 6.1.0. The advisory indicates the issue is fixed in that release. No alternate mitigations (such as configuration changes or patches) are documented in the provided sources. (Sources: 4124, 31825)

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
msgpack5: Quadratic parsing in streaming decoder (CVE-2026-107297)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email