PT-2026-108060 · Mcollina+1 · Msgpack5
CVE-2026-107300
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Impact
The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream.
Patches
The streaming decoder now drains concatenated values iteratively with constant call-stack depth.
Workarounds
Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Msgpack5