Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-26wq-p25c-j6fv | msgpack5: Reserved byte can cause unbounded stream buffering |
Thu, 08 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits for bytes that cannot make the value valid, allowing a remote peer to exhaust memory. This issue is fixed in version 6.1.0. | |
| Title | msgpack5: Reserved byte can cause unbounded stream buffering | |
| Weaknesses | CWE-228 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:09:47.191Z
Reserved: 2026-10-07T15:53:23.587Z
Link: CVE-2026-107299
No data.
Status : Received
Published: 2026-10-08T17:17:15.850
Modified: 2026-10-08T17:17:15.850
Link: CVE-2026-107299
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:00:07Z

Github GHSA