OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-107302: msgpack5: Truncated map32 headers throw an unexpected error

GitHub Advisories · officialPublished Oct 8, 2026Risk 37/100

### Impact A truncated `map32` header causes an out-of-bounds buffer read and throws `RangeError` instead of `IncompleteBufferError`. Applications that rely on `IncompleteBufferError` to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds. ### Patches The decoder now validates the complete five-byte `map32` header before reading its length and reports truncated input as `IncompleteBufferError`. ### Workarounds Require at least five bytes before decoding a value beginning with `0xdf`, or catch `RangeError` and treat it as incomplete input only for truncated `map32` headers.

Upgrade affected packages to a patched version: msgpack5 6.1.0.

Vendor
Not specified
Product
msgpack5
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source