GHSA-qw35-55vc-rhgj: Low severity npm/msgpack5 vulnerability

Published Oct 8, 2026
·
Updated

Impact

Decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. Applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing may observe silently corrupted data.

Positive integers and other MessagePack value types are not affected.

Patches

The decoder now computes signed 64-bit values without writing to the input buffer.

Workarounds

Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.

Affected Software

1 affected componentFixes available
npm/msgpack5<6.1.0
6.1.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/msgpack5 to a version that resolves this vulnerability.

    Fixed in 6.1.0
  2. Compensating control

    Copy untrusted MessagePack input before decoding it, or do not retain or reuse input buffers after decoding.

Event History

Oct 8, 2026
Advisory Published
via GitHub·05:39 PM
Data Sourced
via GitHub·05:39 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications using npm/msgpack5 are exposed when they decode negative signed 64-bit MessagePack integers and retain or reuse the caller-provided input buffer afterward. Positive integers and other MessagePack value types are not affected.

2

Does exploitation require authentication or user interaction?

No authentication or user interaction is required according to the supplied vector. Exploitation requires an attacker-controlled MessagePack payload containing a negative signed 64-bit integer to be decoded.

3

What can be done if the patch cannot be applied immediately?

Copy untrusted MessagePack input before decoding it, or avoid retaining or reusing input buffers after decoding. This prevents the decoder's input-buffer modification from affecting later integrity checks, logging, or processing.

4

How can we determine whether an application may already be affected?

Review decoding paths for caller-provided MessagePack buffers that may contain negative signed 64-bit integers. Focus on cases where the original buffer is later used for integrity validation, logging, or subsequent processing, since those uses may observe silently corrupted bytes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203