CVE-2026-107299: msgpack5: Reserved byte can cause unbounded stream buffering

Published Oct 8, 2026
·
Updated

Impact

The reserved MessagePack byte 0xc1 is incorrectly treated as incomplete input. When it appears at the start of a decoder stream, all subsequent data is retained while the decoder waits for bytes that can never make the value valid, allowing memory exhaustion.

Patches

The decoder now rejects 0xc1 as invalid input. Streaming decoders release buffered input and stop after unrecoverable decoding errors.

Workarounds

Reject 0xc1 before streaming input to msgpack5, and enforce stream byte and time limits.

Other sources

msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0.

— MITRE

Affected Software

2 affected componentsFixes available
npm/msgpack5<6.1.0
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Upgrade

    Upgrade msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  3. Compensating control

    Before passing streaming input to msgpack5, reject the reserved MessagePack byte 0xc1 and enforce stream byte and time limits.

Event History

Oct 8, 2026
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:40 PM
Data Sourced
via GitHub·05:40 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using msgpack5 before version 6.1.0 that accept MessagePack data from remote peers through its streaming decoder are exposed. A remote peer can trigger the condition by starting a stream with the reserved byte 0xc1.

2

What is the impact of successful exploitation?

The decoder continues buffering subsequent stream data while waiting for a value that can never become valid. This can exhaust application memory and cause a denial of service.

3

What should be done if patching cannot happen immediately?

The provided data identifies version 6.1.0 as the fix. No alternative mitigation is specified.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203