CVE-2026-107299
Received
Received - Intake
msgpack5 Streaming Decoder Memory Exhaustion Vulnerability
Vulnerability report for CVE-2026-107299, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: GitHub, Inc.
Description
Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mcollina | msgpack5 | < 6.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-228 | The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification. |