GHSA-gcx5-hxj7-gpqq: Medium severity npm/msgpack5 vulnerability
Impact
The streaming decoder reparses an incomplete container from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack value across many small chunks, causing quadratic CPU usage and blocking the event loop.
Patches
The decoder now preserves incremental container state so completed elements are not parsed again when more input arrives.
Workarounds
Buffer each complete MessagePack value before decoding it, or limit the number of chunks accepted for a single value.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Compensating control
Buffer each complete MessagePack value before decoding, or limit the number of chunks accepted for a single value to prevent quadratic CPU usage and event-loop blocking.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using npm/msgpack5's streaming decoder are exposed if they accept MessagePack data from remote peers. The risk is highest where a peer can control how a valid value is fragmented into input chunks.
What does an attacker need to do to cause the denial of service?
An unauthenticated remote peer needs to send one valid MessagePack value split across many small chunks. Reprocessing of the incomplete container causes quadratic CPU use and can block the event loop.
What can be done if the update cannot be applied immediately?
Buffer each complete MessagePack value before passing it to the decoder, or enforce a limit on the number of chunks accepted for a single value. Either approach prevents excessive incremental reparsing.
How can we tell whether our deployment is affected?
Check whether the application uses msgpack5's streaming decoder and permits remote peers to deliver a single MessagePack value in many chunks. If values are buffered completely before decoding, this specific chunk-fragmentation condition is mitigated.