SB2026092944 - Multiple vulnerabilities in msgpack5
Published: September 29, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Modification of assumed-immutable data (CVE-ID: N/A)
CWE-ID: CWE-471 - Modification of Assumed-Immutable Data
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to modify caller-provided input data.
The vulnerability exists due to modification of assumed-immutable data in the msgpack5 decoder when decoding a negative signed 64-bit integer. A remote attacker can provide specially crafted MessagePack input to modify caller-provided input data.
Positive integers and other MessagePack value types are not affected.
2) Inefficient Algorithmic Complexity (CVE-ID: N/A)
CWE-ID: CWE-407 - Inefficient Algorithmic Complexity
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient algorithmic complexity in the streaming decoder when processing a valid MessagePack value split across many small chunks. A remote attacker can split one valid MessagePack value across many small chunks to cause a denial of service.
The quadratic CPU usage can block the event loop.
3) Uncontrolled Recursion (CVE-ID: N/A)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the msgpack5 decoder when decoding deeply nested MessagePack arrays or maps. A remote attacker can provide deeply nested MessagePack input to cause a denial of service.
4) Prototype pollution (CVE-ID: N/A)
CWE-ID: CWE-1321 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to modify inherited properties of decoded objects or cause unexpected behavior in downstream code.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the msgpack5 decoder when decoding a map containing a __proto__ key with an empty or partial options object. A remote attacker can supply a specially crafted map to modify the prototype of the decoded object.
Only the decoded object's prototype is affected; Object.prototype is not modified globally.
5) Improper Handling of Syntactically Invalid Structure (CVE-ID: N/A)
CWE-ID: CWE-228 - Improper Handling of Syntactically Invalid Structure
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of syntactically invalid structure in the msgpack5 streaming decoder when processing a decoder stream beginning with the reserved MessagePack byte 0xc1. A remote attacker can supply a stream beginning with 0xc1 followed by additional data to cause a denial of service.
6) Uncontrolled Recursion (CVE-ID: N/A)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the streaming decoder when processing a single chunk containing many small valid MessagePack values. A remote attacker can send a crafted chunk containing many concatenated MessagePack values to cause a denial of service.
7) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the msgpack5 decoder when processing a truncated map32 header. A remote attacker can send truncated map32 data to cause a denial of service.
No adjacent memory is disclosed because buffer bounds are checked.
Remediation
Install update from vendor's website.
References
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-qw35-55vc-rhgj
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-24ch-f2g6-9hhh
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-8hq7-ggx2-cc6m
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-26wq-p25c-j6fv
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9
- https://github.com/mcollina/msgpack5/security/advisories/GHSA-8f34-f56x-9xph