PatchSiren cyber security CVE debrief
CVE-2026-107297 mcollina CVE debrief
A remote peer can cause quadratic CPU usage and block the event loop by splitting one valid MessagePack value across many small chunks in the msgpack5 library. The decoder now preserves incremental container state to prevent re-parsing completed elements. Defenders should assess exposure, prioritize remediation, and verify inventory for msgpack5 usage.
- Vendor
- mcollina
- Product
- msgpack5
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for msgpack5 inventory and patch management should assess exposure and prioritize remediation. This includes verifying msgpack5 usage in their inventory, reviewing compensating controls, and tracking exceptions. Security teams should review the vulnerability and its potential impact on their organization, and assign an owner for follow-up.
Why it matters
The msgpack5 library vulnerability can cause significant CPU usage and event loop blocking, requiring defenders to assess exposure, prioritize remediation, and verify inventory.
- CPU usage and event loop blocking require verification and mitigation
- msgpack5 inventory verification is necessary to assess exposure
- Patching to version 6.1.0 or later is recommended to prevent exploitation
Technical summary
The msgpack5 library has a vulnerability in its streaming decoder, causing quadratic CPU usage and blocking the event loop when a remote peer splits a valid MessagePack value across many small chunks. The decoder now preserves incremental container state to prevent re-parsing completed elements. This vulnerability can be mitigated by patching to version 6.1.0 or later, or by implementing workarounds to buffer complete MessagePack values or limit chunks. Defenders should assess exposure and prioritize remediation based on the severity of the vulnerability.
Defensive priority
Medium priority for msgpack5 inventory verification and patching
Recommended defensive actions
- Verify msgpack5 inventory and assess exposure
- Prioritize patching to version 6.1.0 or later
- Implement workarounds to buffer complete MessagePack values or limit chunks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The source corpus provides details on the vulnerability and patches in msgpack5. The CVE record and NVD entry provide additional context. Defenders should verify msgpack5 usage in their inventory and assess exposure to this vulnerability. The vulnerability allows a remote peer to cause quadratic CPU usage and block the event loop by splitting one valid MessagePack value across many small chunks. Evidence from the source corpus and CVE record indicates that the decoder now preserves incremental container state to prevent re-parsing of
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107297 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107297
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107297 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107297
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
msgpack5: Quadratic parsing in the streaming decoder
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-gcx5-hxj7-gpqq.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/releases/tag/v6.1.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.