PT-2026-108060 · Mcollina+1 · Msgpack5

CVE-2026-107300

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Impact

The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream.

Patches

The streaming decoder now drains concatenated values iteratively with constant call-stack depth.

Workarounds

Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107300
GHSA-5X5G-H9X8-2FH9

Affected Products

Msgpack5