Out-of-Bounds Read in msgpack5 Implementation for Node.js and Browser
CVE-2026-107302
7.5HIGH
What is CVE-2026-107302?
The msgpack5 library for Node.js and browser applications contains a vulnerability where the decoder mishandles the four-byte length of a map32 value before confirming the availability of the complete five-byte header. This oversight can lead to an out-of-bounds buffer read, potentially terminating requests or streams unexpectedly during operation. Users are advised to upgrade to version 6.1.0, which addresses this issue and ensures proper error handling without causing disruptions in application functionality.
Affected Version(s)
msgpack5 < 6.1.0
