{"id":"CVE-2026-107297","title":"msgpack5 is a msgpack v5 implementation for node.js and the browser","summary":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePa…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-407"],"vendor":"msgpack5","product":"msgpack5","affected":["msgpack5 < 6.1.0"],"patched":["msgpack5 6.1.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:48:36.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107297","references":[{"url":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4","label":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","label":"security-advisories@github.com"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-gcx5-hxj7-gpqq"}],"tags":["nvd","ghsa","npm","cve.org"],"aliases":["GHSA-gcx5-hxj7-gpqq"],"ecosystem":"npm","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T17:26:19.427864Z"},"ingestedAt":"2026-10-08T17:56:11.715Z","slug":"CVE-2026-107297","body":"## Overview\n\nmsgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107297)\n\nAffected packages:\n\n- `msgpack5 < 6.1.0`\n\nPatched in:\n\n- `msgpack5 6.1.0`\n\nSource: https://github.com/advisories/GHSA-gcx5-hxj7-gpqq","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}