GHSA-qw35-55vc-rhgj: Low severity npm/msgpack5 vulnerability
Impact
Decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. Applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing may observe silently corrupted data.
Positive integers and other MessagePack value types are not affected.
Patches
The decoder now computes signed 64-bit values without writing to the input buffer.
Workarounds
Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Compensating control
Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications using npm/msgpack5 are exposed when they decode negative signed 64-bit MessagePack integers and retain or reuse the caller-provided input buffer afterward. Positive integers and other MessagePack value types are not affected.
Does exploitation require authentication or user interaction?
No authentication or user interaction is required according to the supplied vector. Exploitation requires an attacker-controlled MessagePack payload containing a negative signed 64-bit integer to be decoded.
What can be done if the patch cannot be applied immediately?
Copy untrusted MessagePack input before decoding it, or avoid retaining or reusing input buffers after decoding. This prevents the decoder's input-buffer modification from affecting later integrity checks, logging, or processing.
How can we determine whether an application may already be affected?
Review decoding paths for caller-provided MessagePack buffers that may contain negative signed 64-bit integers. Focus on cases where the original buffer is later used for integrity validation, logging, or subsequent processing, since those uses may observe silently corrupted bytes.