msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-24ch-f2g6-9hhh | msgpack5: Deeply nested input can exhaust the decoder stack |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0. | |
| Title | msgpack5: Deeply nested input can exhaust the decoder stack | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:08:22.022Z
Reserved: 2026-10-07T15:53:23.587Z
Link: CVE-2026-107298
No data.
Status : Received
Published: 2026-10-08T17:17:15.703
Modified: 2026-10-08T17:17:15.703
Link: CVE-2026-107298
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:00:07Z
Weaknesses
Github GHSA