VulnSea

msgpack5 has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 6. The median CVSS is 5.9 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
—
Last 90 days
6 prev 0

Products

  • msgpack5 6
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

msgpack5 vulnerabilities

CVEs affecting msgpack5, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-107302High· 7.5
yesterday

msgpack5 is a msgpack v5 implementation for node.js and the browser

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header ther…

▾ Twilightmsgpack5 · msgpack5via NVD
CVE-2026-107301Medium· 6.5
yesterday

msgpack5 is a msgpack v5 implementation for node.js and the browser

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__…

▾ Sunlitmsgpack5 · msgpack5via NVD
CVE-2026-107299Medium· 5.9
yesterday

msgpack5 is a msgpack v5 implementation for node.js and the browser

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data…

▾ Sunlitmsgpack5 · msgpack5via NVD
CVE-2026-107298Medium· 5.3
yesterday

msgpack5 is a msgpack v5 implementation for node.js and the browser

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers …

▾ Sunlitmsgpack5 · msgpack5via NVD
CVE-2026-107297Medium· 5.9
yesterday

msgpack5 is a msgpack v5 implementation for node.js and the browser

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePa…

▾ Sunlitmsgpack5 · msgpack5via NVD
CVE-2026-107296Low· 3.7
yesterday

msgpack5 is a msgpack v5 implementation for node.js and the browser

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications t…

▾ Sunlitmsgpack5 · msgpack5via NVD
msgpack5 vulnerabilities (CVEs) · VulnSea