Msgpack5 Integer Handling Vulnerability in Node.js Applications
CVE-2026-107296

3.7LOW

Key Information:

Vendor

Mcollina

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107296?

The msgpack5 library, a MessagePack v5 implementation for Node.js and browsers, exhibits a vulnerability in its handling of negative signed 64-bit integers prior to version 6.1.0. When such integers are decoded, the operation inadvertently alters the original bytes in the caller-provided input buffer, leading to potential data integrity issues. Applications that reuse or retain the encoded input for logging, integrity checks, or future processing may unknowingly encounter corrupted data. This flaw does not affect positive integers or other MessagePack value types. Users are advised to update to version 6.1.0 or later to address this issue.

Affected Version(s)

msgpack5 < 6.1.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.