AZL-106854

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106854.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106854
Upstream
Published
2026-10-08T17:17:15Z
Modified
2026-10-09T14:17:20Z
Summary
CVE-2026-107296 affecting package msgpack 3.3.0-1
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.

References

Affected packages

Azure Linux:3 / msgpack

Package

Name
msgpack
Purl
pkg:rpm/azure-linux/msgpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.3.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106854.json"