CVE-2026-107298: msgpack5: Deeply nested input can exhaust the decoder stack
Impact
The decoder has no nesting-depth limit for arrays and maps. An attacker who can provide MessagePack input can use deeply nested containers to exhaust the JavaScript call stack and interrupt the process or request handler.
Patches
The decoder now limits nesting depth to 100 by default and throws Maximum decode depth exceeded. Applications can configure the limit with the maxDepth option.
Workarounds
Reject deeply nested input before decoding, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.
Other sources
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Upgrade
Upgrade
msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Configuration
Configure the decoder's maxDepth option to limit nesting depth; version 6.1.0 uses a default limit of 100.
msgpack5 decoder maxDepth = 100
Event History
Frequently Asked Questions
Which deployments are exposed?
Applications using msgpack5 before 6.1.0 are exposed when they decode MessagePack data that an attacker can supply. The impact can interrupt a process, worker, or request handler.
Does exploitation require authentication or user interaction?
No. The supplied severity vector indicates network reachability, low attack complexity, no privileges required, and no user interaction.
How can I determine whether my application is affected?
Check whether npm/msgpack5 is installed at a version earlier than 6.1.0 and whether the application decodes attacker-controlled MessagePack input. Versions before 6.1.0 have no nesting-depth limit in the array and map decoding paths.
What is the available fix?
Upgrade msgpack5 to version 6.1.0, which fixes the issue.