PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107296 mcollina CVE debrief

The msgpack5 package has a vulnerability where decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. This may cause silently corrupted data in applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing. The issue is caused by the decoder writing to the input buffer when computing signed 64-bit values. Positive integers and other MessagePack value types are not affected. The patched version 6.1.0 computes signed 64-bit values without writing to the input buffer.

Vendor
mcollina
Product
msgpack5
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for maintaining and securing applications that use the msgpack5 package should assess exposure and prioritize verification and remediation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams that use msgpack5 for integrity checks, logging, or subsequent processing.

Why it matters

Defenders should care about this vulnerability because it can cause silently corrupted data in applications that use msgpack5 for integrity checks, logging, or subsequent processing. The vulnerability requires verification and remediation efforts, and defenders should prioritize updating msgpack5 to version 6.1.0 or later and consider implementing workarounds for untrusted input.

  • Data corruption in integrity checks, logging, or subsequent processing due to modified input buffers
  • Potential for silently corrupted data in applications that retain or reuse encoded input
  • Need for verification and updating msgpack5 to version 6.1.0 or later
  • Consideration of workarounds for untrusted input, such as copying input before decoding

Technical summary

The msgpack5 package has a vulnerability where decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. This occurs because the decoder previously wrote to the input buffer when computing signed 64-bit values. The issue affects applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing, potentially causing silently corrupted data. Positive integers and other MessagePack value types are not affected. The decoder now computes signed 64-bit values without writing to the input buffer in the patched version 6.1.0.

Defensive priority

Defenders should prioritize verifying and updating msgpack5 to version 6.1.0 or later, and consider implementing workarounds for untrusted input.

Recommended defensive actions

  • Verify and update msgpack5 to version 6.1.0 or later
  • Implement workarounds for untrusted input, such as copying input before decoding
  • Review and update applications that use msgpack5 for integrity checks, logging, or subsequent processing
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability was reported by an unknown source and is documented in the CVE Program record and the NVD vulnerability detail page. The reporter provided limited information about the vulnerability, but it is clear that the issue affects applications that use msgpack5 for decoding. To verify the vulnerability, defenders should review the official advisory and CVE record, and check for affected product deployments in managed environments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107296 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107296

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107296 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107296

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • msgpack5: Decoding negative int64 values mutates the input buffer

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-qw35-55vc-rhgj.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/security/advisories/GHSA-qw35-55vc-rhgj

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/commit/82b70393a824e1088a45a377548d1d9ab82faf91

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/releases/tag/v6.1.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.