PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107297 mcollina CVE debrief

A remote peer can cause quadratic CPU usage and block the event loop by splitting one valid MessagePack value across many small chunks in the msgpack5 library. The decoder now preserves incremental container state to prevent re-parsing completed elements. Defenders should assess exposure, prioritize remediation, and verify inventory for msgpack5 usage.

Vendor
mcollina
Product
msgpack5
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for msgpack5 inventory and patch management should assess exposure and prioritize remediation. This includes verifying msgpack5 usage in their inventory, reviewing compensating controls, and tracking exceptions. Security teams should review the vulnerability and its potential impact on their organization, and assign an owner for follow-up.

Why it matters

The msgpack5 library vulnerability can cause significant CPU usage and event loop blocking, requiring defenders to assess exposure, prioritize remediation, and verify inventory.

  • CPU usage and event loop blocking require verification and mitigation
  • msgpack5 inventory verification is necessary to assess exposure
  • Patching to version 6.1.0 or later is recommended to prevent exploitation

Technical summary

The msgpack5 library has a vulnerability in its streaming decoder, causing quadratic CPU usage and blocking the event loop when a remote peer splits a valid MessagePack value across many small chunks. The decoder now preserves incremental container state to prevent re-parsing completed elements. This vulnerability can be mitigated by patching to version 6.1.0 or later, or by implementing workarounds to buffer complete MessagePack values or limit chunks. Defenders should assess exposure and prioritize remediation based on the severity of the vulnerability.

Defensive priority

Medium priority for msgpack5 inventory verification and patching

Recommended defensive actions

  • Verify msgpack5 inventory and assess exposure
  • Prioritize patching to version 6.1.0 or later
  • Implement workarounds to buffer complete MessagePack values or limit chunks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The source corpus provides details on the vulnerability and patches in msgpack5. The CVE record and NVD entry provide additional context. Defenders should verify msgpack5 usage in their inventory and assess exposure to this vulnerability. The vulnerability allows a remote peer to cause quadratic CPU usage and block the event loop by splitting one valid MessagePack value across many small chunks. Evidence from the source corpus and CVE record indicates that the decoder now preserves incremental container state to prevent re-parsing of

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107297 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107297

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107297 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107297

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • msgpack5: Quadratic parsing in the streaming decoder

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-gcx5-hxj7-gpqq.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/releases/tag/v6.1.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.