CVE-2026-107300: falha de alta gravidade em mcollina msgpack5
msgpack5: Many buffered values can exhaust the streaming decoder stack
Publicada em
18Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.5
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
mcollina · msgpack5CVEs relacionadas — mcollina msgpack5
No mesmo produto, das mais perigosas para as menos.
CVE-2021-21368MEDIUMPrototype poisoningEPSS 1.6%CVE-2026-107302HIGHmsgpack5: Truncated map32 headers throw an unexpected errorEPSS —CVE-2026-107301MEDIUMmsgpack5: Partial options disable prototype protectionEPSS —CVE-2026-107299MEDIUMmsgpack5: Reserved byte can cause unbounded stream bufferingEPSS —CVE-2026-107298MEDIUMmsgpack5: Deeply nested input can exhaust the decoder stackEPSS —CVE-2026-107297MEDIUMmsgpack5: Quadratic parsing in the streaming decoderEPSS —