Back to database
Soon75High7.5VulnerabilityCVE-2026-107300No patch link observed

CVE-2026-107300 — msgpack5 is a msgpack v5 implementation for node.js and the browser.

Published Oct 8, 2026, 05:17 PM UTCIngested 6h agoSource NVD(cve-db)CVE-2026-107300

Description

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

High

Availability

Affected

Vendor
npm
Product
msgpack5

Versions

  • pkg:npm/msgpack5 < 6.1.0

Stated as the source expressed them.