msgpack5 是适用于 Node.js 和浏览器的 MessagePack v5 实现。在版本 6.1.0 之前,当解码负号 64 位有符号整数时,会在计算其值的过程中修改调用者提供的输入缓冲区中对应的字节。对于保留或重用编码输入数据进行完整性检查、日志记录或后续处理的应用程序,可能会观察到静默损坏的数据;而正整数和其他 MessagePack 数据类型不受此问题影响。该问题已在版本 6.1.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107300 | 7.5 HIGH | msgpack5: Many buffered values can exhaust the streaming decoder stack |
| CVE-2026-107302 | 7.5 HIGH | msgpack5: Truncated map32 headers throw an unexpected error |
| CVE-2026-107301 | 6.5 MEDIUM | msgpack5: Partial options disable prototype protection |
| CVE-2026-107297 | 5.9 MEDIUM | msgpack5: Quadratic parsing in the streaming decoder |
| CVE-2026-107299 | 5.9 MEDIUM | msgpack5: Reserved byte can cause unbounded stream buffering |
| CVE-2026-107298 | 5.3 MEDIUM | msgpack5: Deeply nested input can exhaust the decoder stack |
No comments yet