CVE-2026-107300: fallo de gravedad alta en mcollina msgpack5
msgpack5: Many buffered values can exhaust the streaming decoder stack
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
mcollina · msgpack5CVEs relacionadas — mcollina msgpack5
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-21368MEDIUMPrototype poisoningEPSS 1.6%CVE-2026-107302HIGHmsgpack5: Truncated map32 headers throw an unexpected errorEPSS —CVE-2026-107301MEDIUMmsgpack5: Partial options disable prototype protectionEPSS —CVE-2026-107299MEDIUMmsgpack5: Reserved byte can cause unbounded stream bufferingEPSS —CVE-2026-107298MEDIUMmsgpack5: Deeply nested input can exhaust the decoder stackEPSS —CVE-2026-107297MEDIUMmsgpack5: Quadratic parsing in the streaming decoderEPSS —