PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107298 mcollina CVE debrief

This PatchSiren debrief is based on the supplied source corpus for CVE-2026-107298, which describes a vulnerability in the msgpack5 package. The vulnerability allows an attacker to exhaust the JavaScript call stack by providing deeply nested MessagePack input, potentially interrupting the process or request handler. The decoder now limits nesting depth to 100 by default and throws 'Maximum decode depth exceeded'. Applications can configure this limit using the maxDepth option. To mitigate, reject deeply nested input before decoding, isolate decoding in a worker, or enforce a trusted schema with a bounded nesting depth.

Vendor
mcollina
Product
msgpack5
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems handling MessagePack input from untrusted sources should assess exposure and prioritize verification of msgpack5 usage in their environments, especially in systems handling MessagePack input from untrusted sources. They should also review compensating controls for exposed systems and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Why it matters

Defenders should care about CVE-2026-107298 because it allows an attacker to potentially interrupt processes or request handlers by providing deeply nested MessagePack input. The vulnerability requires verification of msgpack5 usage and configuration in the environment, especially in systems handling MessagePack input from untrusted sources. The impacts include potential interruption of processes or request handlers, need for verification, and possible data processing or service availability impacts if not mitigated.

  • Potential interruption of processes or request handlers due to deeply nested input.
  • Need to verify msgpack5 usage and configuration in the environment.
  • Possible data processing or service availability impacts if not mitigated.

Technical summary

The msgpack5 package has a vulnerability that allows an attacker to exhaust the JavaScript call stack by providing deeply nested MessagePack input. The decoder now limits nesting depth to 100 by default and throws 'Maximum decode depth exceeded'. Applications can configure this limit using the maxDepth option. Defenders should assess exposure and prioritize verification of msgpack5 usage in their environments, especially in systems handling MessagePack input from untrusted sources, and review compensating controls for exposed systems.

Defensive priority

Defenders should assess exposure and prioritize verification of msgpack5 usage in their environments, especially in systems handling MessagePack input from untrusted sources.

Recommended defensive actions

  • Assess exposure by checking if msgpack5 is used in the environment, especially in systems handling MessagePack input from untrusted sources.
  • Verify if the msgpack5 package version is 6.1.0 or later, or if the maxDepth option is configured according to the application's security requirements.
  • Implement workarounds such as rejecting deeply nested input before decoding, isolating decoding in a worker, or enforcing a trusted schema with a bounded nesting depth.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The source corpus provides details on the vulnerability, patches, and workarounds. However, it does not provide information on known victims, exploitation, or specific business impacts. Defenders should verify msgpack5 usage and configuration in their environments, especially in systems handling MessagePack input from untrusted sources, and review compensating controls for exposed systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107298 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107298

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107298 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107298

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • msgpack5: Deeply nested input can exhaust the decoder stack

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-24ch-f2g6-9hhh.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/security/advisories/GHSA-24ch-f2g6-9hhh

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/commit/1e2b5874e555dd7c99417f64788a03b0590bb102

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mcollina/msgpack5/releases/tag/v6.1.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.