MajorCritical vulnerability
CVE-2026-107300: msgpack5: Many buffered values can exhaust the streaming decoder stack
GitHub Advisories · officialPublished Oct 8, 2026Risk 37/100
### Impact The streaming decoder recursively invokes itself for every complete value remaining in a chunk. A single chunk containing many small valid MessagePack values can exhaust the JavaScript call stack and interrupt the process or stream. ### Patches The streaming decoder now drains concatenated values iteratively with constant call-stack depth. ### Workarounds Limit the number of MessagePack values accepted in one chunk, or split large batches before passing them to the decoder stream.
Recommended action
Recommended action
Upgrade affected packages to a patched version: msgpack5 6.1.0.
Technical details
- Vendor
- Not specified
- Product
- msgpack5
- Exploitation
- none known
- Evidence
- official
CVSS
7.5
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source