CVE-2026-107296: msgpack5: Decoding negative int64 values mutates the input buffer

Published Oct 8, 2026
·
Updated

Impact

Decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. Applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing may observe silently corrupted data.

Positive integers and other MessagePack value types are not affected.

Patches

The decoder now computes signed 64-bit values without writing to the input buffer.

Workarounds

Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.

Other sources

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.

— MITRE

Affected Software

2 affected componentsFixes available
npm/msgpack5<6.1.0
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Upgrade

    Upgrade msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  3. Compensating control

    Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.

Event History

Oct 8, 2026
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are affected in practice?

Applications using msgpack5 before 6.1.0 are affected when they decode caller-provided MessagePack data containing a negative signed 64-bit integer. The impact matters when the application retains or reuses the original encoded buffer for integrity checks, logging, or later processing.

2

What input is required to trigger the issue?

An attacker or other input source must cause the application to decode a MessagePack value encoded as a negative signed 64-bit integer. Positive integers and other MessagePack value types are not affected.

3

What can be done if upgrading is not immediately possible?

Avoid reusing the caller-provided input buffer after decoding data that may contain negative signed 64-bit integers. Preserve a separate copy before decoding when the encoded data must later be checked, logged, or processed.

4

How can we determine whether corruption has occurred?

Compare the input buffer before and after decoding a payload containing a negative signed 64-bit integer. On affected versions, the bytes corresponding to that value can differ after decoding.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203