GHSA-8f34-f56x-9xphHighCVSS 7.5

msgpack5: Truncated map32 headers throw an unexpected error

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A truncated map32 header causes an out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError. Applications that rely on IncompleteBufferError to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds.

Patches

The decoder now validates the complete five-byte map32 header before reading its length and reports truncated input as IncompleteBufferError.

Workarounds

Require at least five bytes before decoding a value beginning with 0xdf, or catch RangeError and treat it as incomplete input only for truncated map32 headers.

🎯 Affected products1

  • npm/msgpack5:< 6.1.0

🔗 References (4)