PT-2026-108059 · Pypi · Msgpack5

CVE-2026-107299

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions msgpack5 versions prior to 6.1.0
Description The streaming decoder incorrectly treats the reserved MessagePack byte 0xc1 as incomplete input rather than invalid input. When 0xc1 begins a stream, the decoder buffers all subsequent data while waiting for bytes that cannot make the value valid, which allows a remote peer to cause memory exhaustion.
Recommendations Update to version 6.1.0. Reject 0xc1 before streaming input to msgpack5. Enforce stream byte and time limits.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107299
GHSA-26WQ-P25C-J6FV

Affected Products

Msgpack5