Out-of-Bounds Read in msgpack5 Implementation for Node.js and Browser
CVE-2026-107302

7.5HIGH

Key Information:

Vendor

Mcollina

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107302?

The msgpack5 library for Node.js and browser applications contains a vulnerability where the decoder mishandles the four-byte length of a map32 value before confirming the availability of the complete five-byte header. This oversight can lead to an out-of-bounds buffer read, potentially terminating requests or streams unexpectedly during operation. Users are advised to upgrade to version 6.1.0, which addresses this issue and ensures proper error handling without causing disruptions in application functionality.

Affected Version(s)

msgpack5 < 6.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.