OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-107300: msgpack5: Many buffered values can exhaust the streaming decoder stack

GitHub Advisories · officialPublished Oct 8, 2026Risk 37/100

### Impact The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream. ### Patches The streaming decoder now drains concatenated values iteratively with constant call-stack depth. ### Workarounds Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.

Upgrade affected packages to a patched version: msgpack5 6.1.0.

Vendor
Not specified
Product
msgpack5
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source