CVE-2026-107302
Received Received - Intake

Buffer Read Error in msgpack5 Library

Vulnerability report for CVE-2026-107302, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or worker in applications that wait for additional bytes after IncompleteBufferError. There is no adjacent-memory disclosure because the buffer implementation checks bounds. This issue is fixed in version 6.1.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mcollina msgpack5 < 6.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects msgpack5, a MessagePack v5 implementation for Node.js and browsers. Prior to version 6.1.0, the decoder reads a four-byte length for map32 values without first validating the full five-byte header. A truncated map32 header causes an out-of-bounds buffer read, throwing a RangeError instead of the expected IncompleteBufferError. This can unexpectedly terminate requests, streams, or workers in applications waiting for additional bytes.

Detection Guidance

Detecting this vulnerability requires checking the version of msgpack5 in use. Run npm list msgpack5 or check package.json for versions prior to 6.1.0. If using a vulnerable version, update immediately. No specific network commands are needed as this is a library-level issue.

Impact Analysis

The vulnerability can cause unexpected crashes in applications using msgpack5 versions before 6.1.0. If a truncated map32 header is received, the application may terminate unexpectedly instead of handling the incomplete data gracefully. This could disrupt services, especially in streaming or networked environments.

Mitigation Strategies

Upgrade msgpack5 to version 6.1.0 or later. As a temporary workaround, ensure at least five bytes are available before decoding values starting with 0xdf or catch RangeError and treat it as incomplete input for truncated map32 headers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107302. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart