---
id: CVE-2026-107300
title: msgpack5 is a msgpack v5 implementation for node.js and the browser
summary: >-
  msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to
  6.1.0, the streaming decoder recursively invokes itself for each complete
  MessagePack value remaining in a chunk. A remote peer can send one chunk
  containing m…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
vendor: mcollina
product: msgpack5
affected:
  - msgpack5 < 6.1.0
patched:
  - msgpack5 6.1.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:48:36.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107300'
references:
  - url: >-
      https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba
    label: security-advisories@github.com
  - url: 'https://github.com/mcollina/msgpack5/releases/tag/v6.1.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-5x5g-h9x8-2fh9'
tags:
  - nvd
  - cve.org
  - ghsa
  - npm
aliases:
  - GHSA-5x5g-h9x8-2fh9
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-08T17:52:32.790652Z'
ingestedAt: '2026-10-08T17:56:11.716Z'
---

## Overview

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107300)

Affected packages:

- `msgpack5 < 6.1.0`

Patched in:

- `msgpack5 6.1.0`

Source: https://github.com/advisories/GHSA-5x5g-h9x8-2fh9
