---
id: CVE-2026-107297
title: msgpack5 is a msgpack v5 implementation for node.js and the browser
summary: >-
  msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to
  6.1.0, the streaming decoder reparses an incomplete array or map from the
  beginning whenever another chunk arrives. A remote peer can split one valid
  MessagePa…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-407
vendor: msgpack5
product: msgpack5
affected:
  - msgpack5 < 6.1.0
patched:
  - msgpack5 6.1.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:48:36.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107297'
references:
  - url: >-
      https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4
    label: security-advisories@github.com
  - url: 'https://github.com/mcollina/msgpack5/releases/tag/v6.1.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-gcx5-hxj7-gpqq'
tags:
  - nvd
  - ghsa
  - npm
  - cve.org
aliases:
  - GHSA-gcx5-hxj7-gpqq
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T17:26:19.427864Z'
ingestedAt: '2026-10-08T17:56:11.715Z'
---

## Overview

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107297)

Affected packages:

- `msgpack5 < 6.1.0`

Patched in:

- `msgpack5 6.1.0`

Source: https://github.com/advisories/GHSA-gcx5-hxj7-gpqq
