msgpack5 是一个适用于 Node.js 和浏览器的 MessagePack v5 实现。在版本 6.1.0 之前,如果使用空或部分初始化的 options 对象构造 msgpack5 实例,将禁用默认的 protoAction: 'error' 保护机制。此时,若解码得到的消息包中包含一个 __proto__ 键,该键可能导致解码对象的 prototype 被替换,从而可能改变其继承的属性或影响下游行为(尽管不会全局修改 Object.prototype)。该问题已在版本 6.1.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107300 | 7.5 HIGH | msgpack5: Many buffered values can exhaust the streaming decoder stack |
| CVE-2026-107302 | 7.5 HIGH | msgpack5: Truncated map32 headers throw an unexpected error |
| CVE-2026-107297 | 5.9 MEDIUM | msgpack5: Quadratic parsing in the streaming decoder |
| CVE-2026-107299 | 5.9 MEDIUM | msgpack5: Reserved byte can cause unbounded stream buffering |
| CVE-2026-107298 | 5.3 MEDIUM | msgpack5: Deeply nested input can exhaust the decoder stack |
| CVE-2026-107296 | 3.7 LOW | msgpack5: Decoding negative int64 values mutates the input buffer |
No comments yet