CVE-2026-107302: msgpack5: Truncated map32 headers throw an unexpected error
### Impact A truncated `map32` header causes an out-of-bounds buffer read and throws `RangeError` instead of `IncompleteBufferError`. Applications that rely on `IncompleteBufferError` to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds. ### Patches The decoder now validates the complete five-byte `map32` header before reading its length and reports truncated input as `IncompleteBufferError`. ### Workarounds Require at least five bytes before decoding a value beginning with `0xdf`, or catch `RangeError` and treat it as incomplete input only for truncated `map32` headers.
Recommended action
Recommended action
Upgrade affected packages to a patched version: msgpack5 6.1.0.
Technical details
- Vendor
- Not specified
- Product
- msgpack5
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source