The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream.
The streaming decoder now drains concatenated values iteratively with constant call-stack depth.
Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.
{
"cwe_ids": [
"CWE-674"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T17:40:06Z",
"nvd_published_at": null,
"severity": "HIGH"
}