PatchSiren cyber security CVE debrief
CVE-2026-107296 mcollina CVE debrief
The msgpack5 package has a vulnerability where decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. This may cause silently corrupted data in applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing. The issue is caused by the decoder writing to the input buffer when computing signed 64-bit values. Positive integers and other MessagePack value types are not affected. The patched version 6.1.0 computes signed 64-bit values without writing to the input buffer.
- Vendor
- mcollina
- Product
- msgpack5
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for maintaining and securing applications that use the msgpack5 package should assess exposure and prioritize verification and remediation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams that use msgpack5 for integrity checks, logging, or subsequent processing.
Why it matters
Defenders should care about this vulnerability because it can cause silently corrupted data in applications that use msgpack5 for integrity checks, logging, or subsequent processing. The vulnerability requires verification and remediation efforts, and defenders should prioritize updating msgpack5 to version 6.1.0 or later and consider implementing workarounds for untrusted input.
- Data corruption in integrity checks, logging, or subsequent processing due to modified input buffers
- Potential for silently corrupted data in applications that retain or reuse encoded input
- Need for verification and updating msgpack5 to version 6.1.0 or later
- Consideration of workarounds for untrusted input, such as copying input before decoding
Technical summary
The msgpack5 package has a vulnerability where decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. This occurs because the decoder previously wrote to the input buffer when computing signed 64-bit values. The issue affects applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing, potentially causing silently corrupted data. Positive integers and other MessagePack value types are not affected. The decoder now computes signed 64-bit values without writing to the input buffer in the patched version 6.1.0.
Defensive priority
Defenders should prioritize verifying and updating msgpack5 to version 6.1.0 or later, and consider implementing workarounds for untrusted input.
Recommended defensive actions
- Verify and update msgpack5 to version 6.1.0 or later
- Implement workarounds for untrusted input, such as copying input before decoding
- Review and update applications that use msgpack5 for integrity checks, logging, or subsequent processing
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability was reported by an unknown source and is documented in the CVE Program record and the NVD vulnerability detail page. The reporter provided limited information about the vulnerability, but it is clear that the issue affects applications that use msgpack5 for decoding. To verify the vulnerability, defenders should review the official advisory and CVE record, and check for affected product deployments in managed environments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107296 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107296
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107296 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107296
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
msgpack5: Decoding negative int64 values mutates the input buffer
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-qw35-55vc-rhgj.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/security/advisories/GHSA-qw35-55vc-rhgj
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/commit/82b70393a824e1088a45a377548d1d9ab82faf91
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/releases/tag/v6.1.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.