Msgpack5 Integer Handling Vulnerability in Node.js Applications
CVE-2026-107296
3.7LOW
What is CVE-2026-107296?
The msgpack5 library, a MessagePack v5 implementation for Node.js and browsers, exhibits a vulnerability in its handling of negative signed 64-bit integers prior to version 6.1.0. When such integers are decoded, the operation inadvertently alters the original bytes in the caller-provided input buffer, leading to potential data integrity issues. Applications that reuse or retain the encoded input for logging, integrity checks, or future processing may unknowingly encounter corrupted data. This flaw does not affect positive integers or other MessagePack value types. Users are advised to update to version 6.1.0 or later to address this issue.
Affected Version(s)
msgpack5 < 6.1.0
