GHSA-24ch-f2g6-9hhh: Medium severity npm/msgpack5 vulnerability

Published Oct 8, 2026
·
Updated

Impact

The decoder has no nesting-depth limit for arrays and maps. An attacker who can provide MessagePack input can use deeply nested containers to exhaust the JavaScript call stack and interrupt the process or request handler.

Patches

The decoder now limits nesting depth to 100 by default and throws Maximum decode depth exceeded. Applications can configure the limit with the maxDepth option.

Workarounds

Reject deeply nested input before decoding, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.

Affected Software

1 affected componentFixes available
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Configuration

    Configure the decoder's maxDepth option to limit nesting depth to 100 or another bounded value.

    MessagePack decoder maxDepth = 100
  3. Compensating control

    Reject deeply nested MessagePack input before decoding.

  4. Compensating control

    Isolate MessagePack decoding in a worker.

  5. Compensating control

    Enforce a trusted schema with a bounded nesting depth.

Event History

Oct 8, 2026
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

Any attacker able to supply MessagePack input to an application using the affected decoder can trigger it. No authentication or user interaction is required according to the supplied severity vector.

2

What is the practical impact of exploitation?

Deeply nested arrays or maps can exhaust the JavaScript call stack, interrupting the process or the request handler. The provided data describes an availability impact only, with no confidentiality or integrity impact.

3

What changes in the patched decoder?

The decoder limits nesting depth to 100 by default and throws "Maximum decode depth exceeded" when that limit is exceeded. Applications can adjust the limit through the maxDepth option.

4

What can be done if patching is not immediately possible?

Reject deeply nested input before it reaches the decoder, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203