AZL-106857

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106857.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106857
Upstream
Published
2026-10-08T17:17:16Z
Modified
2026-10-11T05:36:19Z
Summary
CVE-2026-107301 affecting package msgpack 3.3.0-1
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a proto key can then replace the decoded object's prototype, potentially changing inherited properties or downstream behavior, although Object.prototype is not modified globally. This issue is fixed in version 6.1.0.

References

Affected packages

Azure Linux:3 / msgpack

Package

Name
msgpack
Purl
pkg:rpm/azure-linux/msgpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.3.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106857.json"