PT-2026-108058 · Npm · Msgpack5

CVE-2026-107298

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions msgpack5 versions prior to 6.1.0
Description The array and map decoding paths lack a nesting-depth limit. An attacker providing MessagePack input can submit deeply nested containers to exhaust the JavaScript call stack, which interrupts the process, worker, or request handler.
Recommendations Update to version 6.1.0. Reject deeply nested input before decoding. Isolate decoding in a worker. Enforce a trusted schema with a bounded nesting depth.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107298
GHSA-24CH-F2G6-9HHH

Affected Products

Msgpack5