CVE-2026-107296
Received Received - Intake

Integer Underflow in msgpack5 Leading to Data Corruption

Vulnerability report for CVE-2026-107296, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mcollina msgpack5 < 6.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-471 The product does not properly protect an assumed-immutable element from being modified by an attacker.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

msgpack5 is a MessagePack v5 implementation for Node.js and browsers. Prior to version 6.1.0, decoding a negative 64-bit integer modifies the input buffer bytes during value computation. This silently corrupts the original data, affecting integrity checks or later processing. Positive integers and other MessagePack types are unaffected.

Detection Guidance

This vulnerability affects msgpack5 versions prior to 6.1.0. To detect it, check the installed version of msgpack5 in your Node.js environment using: npm list msgpack5. If the version is below 6.1.0, the system is vulnerable.

Impact Analysis

If you use msgpack5 versions before 6.1.0, decoding negative 64-bit integers may corrupt your input data. This could lead to incorrect processing, failed integrity checks, or data loss in applications relying on the original buffer.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR or HIPAA by potentially corrupting data integrity during processing. If an application relies on unmodified input buffers for logging, integrity checks, or audit trails, corrupted data from this issue might lead to inaccurate records or failed compliance verifications. However, the direct impact is limited as the issue only affects negative 64-bit integers and has a low CVSS score.

Mitigation Strategies

Upgrade msgpack5 to version 6.1.0 or later immediately. Use the command: npm update msgpack5. If direct updates are not possible, consider removing or replacing the vulnerable package in your project dependencies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107296. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart