GHSA-5x5g-h9x8-2fh9

Suggest an improvement
Source
https://github.com/advisories/GHSA-5x5g-h9x8-2fh9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-5x5g-h9x8-2fh9/GHSA-5x5g-h9x8-2fh9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5x5g-h9x8-2fh9
Aliases
  • CVE-2026-107300
Published
2026-10-08T17:40:06Z
Modified
2026-10-08T18:00:08Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
msgpack5: Many buffered values can exhaust the streaming decoder stack
Details

Impact

The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream.

Patches

The streaming decoder now drains concatenated values iteratively with constant call-stack depth.

Workarounds

Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.

Database specific
{
    "cwe_ids": [
        "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T17:40:06Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / msgpack5

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-5x5g-h9x8-2fh9/GHSA-5x5g-h9x8-2fh9.json"