PT-2026-108056 · Mcollina+1 · Msgpack5

CVE-2026-107296

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions msgpack5 versions prior to 6.1.0
Description Decoding a negative signed 64-bit integer modifies the bytes in the input buffer provided by the caller during value computation. This can lead to silent data corruption for applications that reuse or retain the encoded input for logging, integrity checks, or further processing. Positive integers and other MessagePack value types are not affected.
Recommendations Update to version 6.1.0. Copy untrusted MessagePack input before decoding it. Avoid retaining or reusing input buffers after the decoding process.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107296
GHSA-QW35-55VC-RHGJ

Affected Products

Msgpack5