msgpack5 是适用于 Node.js 和浏览器的 MessagePack v5 实现。在 6.1.0 版本之前,流式解码器将保留的 MessagePack 字节 0xc1 视为不完整的输入,而不是无效的输入。当 0xc1 出现在数据流开头时,后续数据会被持续缓冲,而解码器则在等待无法使该值变为合法的字节。这可能导致远程对等方通过耗尽内存来发起拒绝服务攻击。此问题已在 6.1.0 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107300 | 7.5 HIGH | msgpack5: Many buffered values can exhaust the streaming decoder stack |
| CVE-2026-107302 | 7.5 HIGH | msgpack5: Truncated map32 headers throw an unexpected error |
| CVE-2026-107301 | 6.5 MEDIUM | msgpack5: Partial options disable prototype protection |
| CVE-2026-107297 | 5.9 MEDIUM | msgpack5: Quadratic parsing in the streaming decoder |
| CVE-2026-107298 | 5.3 MEDIUM | msgpack5: Deeply nested input can exhaust the decoder stack |
| CVE-2026-107296 | 3.7 LOW | msgpack5: Decoding negative int64 values mutates the input buffer |
No comments yet