Recursion Vulnerability in msgpack5 for Node.js and Browser
CVE-2026-107300

7.5HIGH

Key Information:

Vendor

Mcollina

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107300?

The msgpack5 library, used for encoding and decoding MessagePack data in Node.js and browser environments, exhibits a vulnerability prior to version 6.1.0. This issue arises from the streaming decoder's recursive call on valid MessagePack values in a single chunk. An attacker can exploit this vulnerability by sending numerous small, valid values in one chunk, leading to excessive recursion and exhausting the JavaScript call stack. This results in potential disruption of processes or streams, impacting the reliability of applications using the library. The issue has been resolved in version 6.1.0.

Affected Version(s)

msgpack5 < 6.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.