GHSA-gcx5-hxj7-gpqq: Medium severity npm/msgpack5 vulnerability

Published Oct 8, 2026
·
Updated

Impact

The streaming decoder reparses an incomplete container from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack value across many small chunks, causing quadratic CPU usage and blocking the event loop.

Patches

The decoder now preserves incremental container state so completed elements are not parsed again when more input arrives.

Workarounds

Buffer each complete MessagePack value before decoding it, or limit the number of chunks accepted for a single value.

Affected Software

1 affected componentFixes available
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Compensating control

    Buffer each complete MessagePack value before decoding, or limit the number of chunks accepted for a single value to prevent quadratic CPU usage and event-loop blocking.

Event History

Oct 8, 2026
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using npm/msgpack5's streaming decoder are exposed if they accept MessagePack data from remote peers. The risk is highest where a peer can control how a valid value is fragmented into input chunks.

2

What does an attacker need to do to cause the denial of service?

An unauthenticated remote peer needs to send one valid MessagePack value split across many small chunks. Reprocessing of the incomplete container causes quadratic CPU use and can block the event loop.

3

What can be done if the update cannot be applied immediately?

Buffer each complete MessagePack value before passing it to the decoder, or enforce a limit on the number of chunks accepted for a single value. Either approach prevents excessive incremental reparsing.

4

How can we tell whether our deployment is affected?

Check whether the application uses msgpack5's streaming decoder and permits remote peers to deliver a single MessagePack value in many chunks. If values are buffered completely before decoding, this specific chunk-fragmentation condition is mitigated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203