PT-2026-108056 · Mcollina+1 · Msgpack5
CVE-2026-107296
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
msgpack5 versions prior to 6.1.0
Description
Decoding a negative signed 64-bit integer modifies the bytes in the input buffer provided by the caller during value computation. This can lead to silent data corruption for applications that reuse or retain the encoded input for logging, integrity checks, or further processing. Positive integers and other MessagePack value types are not affected.
Recommendations
Update to version 6.1.0.
Copy untrusted MessagePack input before decoding it.
Avoid retaining or reusing input buffers after the decoding process.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Msgpack5