CVE-2026-107296: msgpack5: Decoding negative int64 values mutates the input buffer
Impact
Decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. Applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing may observe silently corrupted data.
Positive integers and other MessagePack value types are not affected.
Patches
The decoder now computes signed 64-bit values without writing to the input buffer.
Workarounds
Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.
Other sources
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Upgrade
Upgrade
msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Compensating control
Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.
Event History
Frequently Asked Questions
Which applications are affected in practice?
Applications using msgpack5 before 6.1.0 are affected when they decode caller-provided MessagePack data containing a negative signed 64-bit integer. The impact matters when the application retains or reuses the original encoded buffer for integrity checks, logging, or later processing.
What input is required to trigger the issue?
An attacker or other input source must cause the application to decode a MessagePack value encoded as a negative signed 64-bit integer. Positive integers and other MessagePack value types are not affected.
What can be done if upgrading is not immediately possible?
Avoid reusing the caller-provided input buffer after decoding data that may contain negative signed 64-bit integers. Preserve a separate copy before decoding when the encoded data must later be checked, logged, or processed.
How can we determine whether corruption has occurred?
Compare the input buffer before and after decoding a payload containing a negative signed 64-bit integer. On affected versions, the bytes corresponding to that value can differ after decoding.