msgpack5
npm8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting msgpack5page 1 of 1
- CVE-2021-21368MEDIUMCVSS 6.7EG 6.7fixed in 3.6.1, 4.5.1 or 5.2.1, by version range2021-03-12
msgpack5 is a msgpack v5 implementation for node.js and the browser. In msgpack5 before versions 3.6.1, 4.5.1, and 5.2.1 there is a "Prototype Poisoning" vulnerability. When msgpack5 decodes a map containing a key "__proto__", it assigns t…
- CVE-2026-107296LOWCVSS 3.7EG 3.7fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications tha…
- CVE-2026-107297MEDIUMCVSS 5.9EG 5.9fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack…
- CVE-2026-107298MEDIUMCVSS 5.3EG 5.3fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers th…
- CVE-2026-107299MEDIUMCVSS 5.9EG 5.9fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data r…
- CVE-2026-107300HIGHCVSS 7.5EG 7.5fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing man…
- CVE-2026-107301MEDIUMCVSS 6.5EG 6.5fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ k…
- CVE-2026-107302HIGHCVSS 7.5EG 7.5fixed in 6.1.02026-10-08
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header theref…
Check whether msgpack5 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for msgpack5 CVEs against the assets you own.
Book a Demo →