AZL-106842

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106842.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106842
Upstream
Published
2026-10-08T17:17:15Z
Modified
2026-10-09T14:17:20Z
Summary
CVE-2026-107297 affecting package msgpack 3.3.0-1
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.

References

Affected packages

Azure Linux:3 / msgpack

Package

Name
msgpack
Purl
pkg:rpm/azure-linux/msgpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.3.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106842.json"