AZL-106851

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106851.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106851
Upstream
Published
2026-10-08T17:17:16Z
Modified
2026-10-09T14:17:20Z
Summary
CVE-2026-107300 affecting package msgpack 3.3.0-1
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.

References

Affected packages

Azure Linux:3 / msgpack

Package

Name
msgpack
Purl
pkg:rpm/azure-linux/msgpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.3.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106851.json"