GHSA-24ch-f2g6-9hhh: Medium severity npm/msgpack5 vulnerability
Impact
The decoder has no nesting-depth limit for arrays and maps. An attacker who can provide MessagePack input can use deeply nested containers to exhaust the JavaScript call stack and interrupt the process or request handler.
Patches
The decoder now limits nesting depth to 100 by default and throws Maximum decode depth exceeded. Applications can configure the limit with the maxDepth option.
Workarounds
Reject deeply nested input before decoding, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Configuration
Configure the decoder's maxDepth option to limit nesting depth to 100 or another bounded value.
MessagePack decoder maxDepth = 100 - Compensating control
Reject deeply nested MessagePack input before decoding.
- Compensating control
Isolate MessagePack decoding in a worker.
- Compensating control
Enforce a trusted schema with a bounded nesting depth.
Event History
Frequently Asked Questions
Who can exploit this issue?
Any attacker able to supply MessagePack input to an application using the affected decoder can trigger it. No authentication or user interaction is required according to the supplied severity vector.
What is the practical impact of exploitation?
Deeply nested arrays or maps can exhaust the JavaScript call stack, interrupting the process or the request handler. The provided data describes an availability impact only, with no confidentiality or integrity impact.
What changes in the patched decoder?
The decoder limits nesting depth to 100 by default and throws "Maximum decode depth exceeded" when that limit is exceeded. Applications can adjust the limit through the maxDepth option.
What can be done if patching is not immediately possible?
Reject deeply nested input before it reaches the decoder, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.