CVE-2026-107298
Received Received - Intake

Memory Exhaustion in msgpack5 via Deeply Nested Structures

Vulnerability report for CVE-2026-107298, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mcollina msgpack5 < 6.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the msgpack5 library versions prior to 6.1.0. It allows attackers to provide deeply nested MessagePack input that exhausts the JavaScript call stack, causing a denial of service by interrupting processes, workers, or request handlers. The decoder lacks a nesting-depth limit for arrays and maps.

Detection Guidance

To detect this vulnerability, monitor for crashes or hangs in applications using msgpack5 versions prior to 6.1.0 when processing MessagePack input. Check npm package versions with 'npm list msgpack5' or inspect package.json for dependencies. Test with deeply nested MessagePack data to observe stack exhaustion or process interruption.

Impact Analysis

An attacker could exploit this to crash your application by sending specially crafted MessagePack data with excessive nesting. This could disrupt services, cause downtime, or require manual intervention to restart processes. The impact is primarily on system availability.

Compliance Impact

This vulnerability primarily impacts availability by causing denial of service through stack exhaustion, which could disrupt services handling sensitive data. While not directly violating GDPR or HIPAA, prolonged downtime may lead to non-compliance with availability requirements under these regulations. Organizations must ensure patched versions are deployed to maintain service continuity.

Mitigation Strategies

Upgrade msgpack5 to version 6.1.0 or later using 'npm update msgpack5'. If upgrading is not possible, implement input validation to reject deeply nested MessagePack data before decoding. Alternatively, isolate decoding in a worker process or enforce a trusted schema with a bounded nesting depth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107298. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart