PT-2026-108060 · Mcollina+1 · Msgpack5
CVE-2026-107300
·
Publicado
2026-10-08
·
Atualizado
2026-10-08
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Impact
The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream.
Patches
The streaming decoder now drains concatenated values iteratively with constant call-stack depth.
Workarounds
Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.
Correção
Uncontrolled Recursion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Msgpack5