CVE-2026-107296

Source
https://cve.org/CVERecord?id=CVE-2026-107296
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107296.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107296
Aliases
Published
2026-10-08T17:05:34Z
Modified
2026-10-09T02:49:21Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
msgpack5: Decoding negative int64 values mutates the input buffer
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-471"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107296.json"
}
References

Affected packages

Git / github.com/mcollina/msgpack5

Affected ranges

Type
GIT
Repo
https://github.com/mcollina/msgpack5
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.1.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.2.0
v1.3.1
v1.3.2
v1.5.0
v1.6.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v3.*
v3.0.0
v3.1.0
v3.2.0
v3.3.0
v3.4.0
v3.4.1
v3.5.0
v3.6.0
v3.6.1
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.2.0
v4.3.0
v4.4.0
v5.*
v5.0.0
v5.1.0
v5.2.0
v5.2.1
v5.3.0
v5.3.1
v5.3.2
v6.*
v6.0.0
v6.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107296.json"