msgpack5 has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 6. The median CVSS is 5.9 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Weakness classes
Products
- msgpack5 6
Worst active — by depth score
CVE-2026-107302High· 7.5msgpack5 is a msgpack v5 implementation for node.js and the browser41CVE-2026-107301Medium· 6.5msgpack5 is a msgpack v5 implementation for node.js and the browser36CVE-2026-107299Medium· 5.9msgpack5 is a msgpack v5 implementation for node.js and the browser32CVE-2026-107297Medium· 5.9msgpack5 is a msgpack v5 implementation for node.js and the browser32CVE-2026-107298Medium· 5.3msgpack5 is a msgpack v5 implementation for node.js and the browser29
msgpack5 vulnerabilities
CVEs affecting msgpack5, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-107302High· 7.5msgpack5 is a msgpack v5 implementation for node.js and the browser
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header ther…
CVE-2026-107301Medium· 6.5msgpack5 is a msgpack v5 implementation for node.js and the browser
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__…
CVE-2026-107299Medium· 5.9msgpack5 is a msgpack v5 implementation for node.js and the browser
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data…
CVE-2026-107298Medium· 5.3msgpack5 is a msgpack v5 implementation for node.js and the browser
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers …
CVE-2026-107297Medium· 5.9msgpack5 is a msgpack v5 implementation for node.js and the browser
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePa…
CVE-2026-107296Low· 3.7msgpack5 is a msgpack v5 implementation for node.js and the browser
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications t…