CVE-2026-107297: msgpack5: Quadratic parsing in the streaming decoder

Published Oct 8, 2026
·
Updated

Impact

The streaming decoder reparses an incomplete container from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack value across many small chunks, causing quadratic CPU usage and blocking the event loop.

Patches

The decoder now preserves incremental container state so completed elements are not parsed again when more input arrives.

Workarounds

Buffer each complete MessagePack value before decoding it, or limit the number of chunks accepted for a single value.

Other sources

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.

— MITRE

Affected Software

2 affected componentsFixes available
npm/msgpack5<6.1.0
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Upgrade

    Upgrade msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  3. Compensating control

    Buffer each complete MessagePack value before decoding it, or limit the number of chunks accepted for a single value.

Event History

Oct 8, 2026
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using msgpack5 versions prior to 6.1.0 are exposed when they use the streaming decoder on data received from a remote peer. The issue affects both Node.js and browser use of msgpack5.

2

What must an attacker do to trigger the problem?

An attacker needs to send a valid MessagePack array or map split across many small chunks. Each additional chunk can cause the decoder to reprocess already completed elements, consuming increasing CPU time.

3

What is the remediation?

Upgrade msgpack5 to version 6.1.0, which fixes the streaming decoder behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203