CVE-2026-107300

Source
https://cve.org/CVERecord?id=CVE-2026-107300
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107300.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107300
Aliases
Downstream
Published
2026-10-08T17:11:13Z
Modified
2026-10-09T02:49:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
msgpack5: Many buffered values can exhaust the streaming decoder stack
Details

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-674"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107300.json"
}
References

Affected packages

Git / github.com/mcollina/msgpack5

Affected ranges

Type
GIT
Repo
https://github.com/mcollina/msgpack5
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.1.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.2.0
v1.3.1
v1.3.2
v1.5.0
v1.6.0
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v3.*
v3.0.0
v3.1.0
v3.2.0
v3.3.0
v3.4.0
v3.4.1
v3.5.0
v3.6.0
v3.6.1
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.2.0
v4.3.0
v4.4.0
v5.*
v5.0.0
v5.1.0
v5.2.0
v5.2.1
v5.3.0
v5.3.1
v5.3.2
v6.*
v6.0.0
v6.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107300.json"