PatchSiren cyber security CVE debrief
CVE-2026-107299 mcollina CVE debrief
A memory exhaustion vulnerability exists in msgpack5 due to incorrect handling of the reserved MessagePack byte `0xc1`. When this byte appears at the start of a decoder stream, the decoder retains all subsequent data, waiting for bytes that can never make the value valid. This issue allows for potential memory exhaustion. The decoder now rejects `0xc1` as invalid input, and streaming decoders release buffered input and stop after unrecoverable decoding errors. Users can reject `0xc1` before streaming input to msgpack5 and enforce stream byte and time limits as a workaround.
- Vendor
- mcollina
- Product
- msgpack5
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for msgpack5 deployments should assess exposure and apply patches or workarounds to prevent potential memory exhaustion. This includes verifying msgpack5 versions, reviewing compensating controls for exposed systems, and enforcing stream byte and time limits. Security teams and vulnerability management teams should prioritize verifying msgpack5 versions and applying patches or workarounds to prevent potential memory exhaustion.
Why it matters
Defenders should prioritize verifying msgpack5 versions and applying patches or workarounds to prevent potential memory exhaustion due to incorrect handling of the reserved MessagePack byte `0xc1`.
- Potential memory exhaustion due to incorrect handling of reserved MessagePack byte
- Verification of msgpack5 versions and application of patches or workarounds is necessary
Technical summary
The msgpack5 library incorrectly handles the reserved MessagePack byte `0xc1`, allowing for potential memory exhaustion. The issue is addressed in version 6.1.0. This incorrect handling occurs when the reserved MessagePack byte `0xc1` appears at the start of a decoder stream, causing the decoder to retain all subsequent data while waiting for bytes that can never make the value valid. This can lead to memory exhaustion. The decoder now rejects `0xc1` as invalid input, and streaming decoders release buffered input and stop after unrecoverable decoding errors. Users can reject `0xc1` before streaming input to msgpack5 and enforce stream byte and time limits as a workaround.
Defensive priority
Defenders should prioritize verifying msgpack5 versions and applying patches or workarounds to prevent potential memory exhaustion.
Recommended defensive actions
- Verify msgpack5 versions and apply patches or workarounds to prevent potential memory exhaustion
- Reject `0xc1` before streaming input to msgpack5
- Enforce stream byte and time limits
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by the incorrect handling of the reserved MessagePack byte `0xc1`. The decoder's behavior allows for memory exhaustion when this byte appears at the start of a decoder stream. The issue is addressed by rejecting `0xc1` as invalid input and releasing buffered input after unrecoverable decoding errors.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107299 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107299
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107299 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107299
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
msgpack5: Reserved byte can cause unbounded stream buffering
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-26wq-p25c-j6fv.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/security/advisories/GHSA-26wq-p25c-j6fv
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/commit/85da345bf1acc18ca441741e5cf4aa0ed0d69314
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/mcollina/msgpack5/releases/tag/v6.1.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.