CVE-2026-107298: msgpack5: Deeply nested input can exhaust the decoder stack

Published Oct 8, 2026
·
Updated

Impact

The decoder has no nesting-depth limit for arrays and maps. An attacker who can provide MessagePack input can use deeply nested containers to exhaust the JavaScript call stack and interrupt the process or request handler.

Patches

The decoder now limits nesting depth to 100 by default and throws Maximum decode depth exceeded. Applications can configure the limit with the maxDepth option.

Workarounds

Reject deeply nested input before decoding, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.

Other sources

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.

— MITRE

Affected Software

2 affected componentsFixes available
npm/msgpack5<6.1.0
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Upgrade

    Upgrade msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  3. Configuration

    Configure the decoder's maxDepth option to limit nesting depth; version 6.1.0 uses a default limit of 100.

    msgpack5 decoder maxDepth = 100

Event History

Oct 8, 2026
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Applications using msgpack5 before 6.1.0 are exposed when they decode MessagePack data that an attacker can supply. The impact can interrupt a process, worker, or request handler.

2

Does exploitation require authentication or user interaction?

No. The supplied severity vector indicates network reachability, low attack complexity, no privileges required, and no user interaction.

3

How can I determine whether my application is affected?

Check whether npm/msgpack5 is installed at a version earlier than 6.1.0 and whether the application decodes attacker-controlled MessagePack input. Versions before 6.1.0 have no nesting-depth limit in the array and map decoding paths.

4

What is the available fix?

Upgrade msgpack5 to version 6.1.0, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203