CVE-2026-107299: Mcollina MSGPACK5
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.
Affected products
- Mcollina MSGPACK5: before 6.1.0 (fixed in 6.1.0)
Published 2026-10-08. Last modified 2026-10-09.