MessagePack v5 Implementation Vulnerability in Node.js and Browser by Msgpack5
CVE-2026-107297
5.9MEDIUM
What is CVE-2026-107297?
The msgpack5 library, an implementation of MessagePack for Node.js and the browser, contains a vulnerability that arises prior to version 6.1.0. When utilizing its streaming decoder, the library attempts to reparse an incomplete array or map from the start whenever a new data chunk is received. This leads to a situation where a remote peer can effectively split a valid MessagePack container into multiple small segments. Consequently, as the streaming decoder processes these chunks, it may repeatedly decode completed elements, resulting in a significant increase in CPU utilization and potentially blocking the event loop. This issue has been addressed in version 6.1.0.
Affected Version(s)
msgpack5 < 6.1.0
