msgpack5 是用于 Node.js 和浏览器的 MessagePack v5 实现。在版本 6.1.0 之前,解码器在验证完整的五字节 map32 头是否可用之前,会先读取 map32 值的四字节长度字段。因此,若遇到截断的 map32 头,将导致受检的越界缓冲区读取,并抛出 RangeError 异常,而非 IncompleteBufferError 异常。对于在捕获 IncompleteBufferError 后会等待更多字节的应用程序而言,这种异常行为可能导致请求、流或工作进程意外终止。由于缓冲区实现本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107300 | 7.5 HIGH | msgpack5: Many buffered values can exhaust the streaming decoder stack |
| CVE-2026-107301 | 6.5 MEDIUM | msgpack5: Partial options disable prototype protection |
| CVE-2026-107297 | 5.9 MEDIUM | msgpack5: Quadratic parsing in the streaming decoder |
| CVE-2026-107299 | 5.9 MEDIUM | msgpack5: Reserved byte can cause unbounded stream buffering |
| CVE-2026-107298 | 5.3 MEDIUM | msgpack5: Deeply nested input can exhaust the decoder stack |
| CVE-2026-107296 | 3.7 LOW | msgpack5: Decoding negative int64 values mutates the input buffer |
No comments yet