msgpack5 是一个适用于 Node.js 和浏览器的 MessagePack v5 实现。在版本 6.1.0 之前,其数组和解码路径中的嵌套深度没有限制,攻击者若能提供 MessagePack 格式的输入数据,即可提交深层嵌套的容器结构,从而耗尽 JavaScript 调用栈,导致进程、工作线程或请求处理程序中断。该问题已在 6.1.0 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107300 | 7.5 HIGH | msgpack5: Many buffered values can exhaust the streaming decoder stack |
| CVE-2026-107302 | 7.5 HIGH | msgpack5: Truncated map32 headers throw an unexpected error |
| CVE-2026-107301 | 6.5 MEDIUM | msgpack5: Partial options disable prototype protection |
| CVE-2026-107297 | 5.9 MEDIUM | msgpack5: Quadratic parsing in the streaming decoder |
| CVE-2026-107299 | 5.9 MEDIUM | msgpack5: Reserved byte can cause unbounded stream buffering |
| CVE-2026-107296 | 3.7 LOW | msgpack5: Decoding negative int64 values mutates the input buffer |
No comments yet