GHSA-8f34-f56x-9xph: High severity npm/msgpack5 vulnerability

Published Oct 8, 2026
·
Updated

Impact

A truncated map32 header causes an out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError. Applications that rely on IncompleteBufferError to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds.

Patches

The decoder now validates the complete five-byte map32 header before reading its length and reports truncated input as IncompleteBufferError.

Workarounds

Require at least five bytes before decoding a value beginning with 0xdf, or catch RangeError and treat it as incomplete input only for truncated map32 headers.

Affected Software

1 affected componentFixes available
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Compensating control

    Require at least five bytes before decoding a value beginning with 0xdf to prevent truncated map32 headers from causing an out-of-bounds read.

  3. Compensating control

    Catch RangeError and treat it as incomplete input only for truncated map32 headers.

Event History

Oct 8, 2026
Advisory Published
via GitHub·05:40 PM
Data Sourced
via GitHub·05:40 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to disruption?

Applications that decode untrusted or incomplete MessagePack input with msgpack5 and depend on IncompleteBufferError to wait for more bytes are exposed. A truncated map32 header can instead raise RangeError, causing a request, stream, or worker to terminate unexpectedly if that error is not handled.

2

What input is needed to trigger the issue?

An attacker needs to supply truncated MessagePack input beginning with the map32 marker byte 0xdf. The decoder attempts to read the map length before confirming that the full five-byte map32 header is available.

3

What can be done before patching?

Before decoding a value that begins with 0xdf, require at least five bytes to be available. Alternatively, catch RangeError and treat it as incomplete input only when it results from a truncated map32 header.

4

Does this expose adjacent memory contents?

No. The out-of-bounds read is checked by the buffer implementation, so it throws RangeError rather than disclosing adjacent memory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203