Recursion Vulnerability in msgpack5 for Node.js and Browser
CVE-2026-107300
7.5HIGH
What is CVE-2026-107300?
The msgpack5 library, used for encoding and decoding MessagePack data in Node.js and browser environments, exhibits a vulnerability prior to version 6.1.0. This issue arises from the streaming decoder's recursive call on valid MessagePack values in a single chunk. An attacker can exploit this vulnerability by sending numerous small, valid values in one chunk, leading to excessive recursion and exhausting the JavaScript call stack. This results in potential disruption of processes or streams, impacting the reliability of applications using the library. The issue has been resolved in version 6.1.0.
Affected Version(s)
msgpack5 < 6.1.0
