PatchSiren

mcollina CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH mcollina CVE published 2026-10-08

CVE-2026-107302

A vulnerability in the msgpack5 package causes truncated map32 headers to throw an unexpected RangeError instead of IncompleteBufferError, potentially terminating requests, streams, or workers unexpectedly due to incorrect handling. The issue is addressed in version 6.1.0, which validates the complete five-byte map32 header before reading its length and reports truncated input as IncompleteBufferError. De [truncated]

HIGH mcollina CVE published 2026-10-08

CVE-2026-107300

A vulnerability in the msgpack5 package can cause a denial of service when processing a chunk with many small MessagePack values. The vulnerability is caused by the recursive invocation of the streaming decoder for every complete value remaining in a chunk, which can exhaust the JavaScript call stack and interrupt the process or stream. Defenders should assess exposure and prioritize verification and reme [truncated]

MEDIUM mcollina CVE published 2026-10-08

CVE-2026-107299

A memory exhaustion vulnerability exists in msgpack5 due to incorrect handling of the reserved MessagePack byte `0xc1`. When this byte appears at the start of a decoder stream, the decoder retains all subsequent data, waiting for bytes that can never make the value valid. This issue allows for potential memory exhaustion. The decoder now rejects `0xc1` as invalid input, and streaming decoders release buff [truncated]

MEDIUM mcollina CVE published 2026-10-08

CVE-2026-107301

The CVE record for msgpack5: Partial options disable prototype protection was published on 2026-10-08T17:39:57.000Z and has not been modified since then. The NVD entry is currently 6.5 MEDIUM. This vulnerability affects msgpack5, potentially leading to unexpected behavior in downstream code due to prototype changes. Defenders should assess exposure and verify patched versions, particularly for npm package [truncated]

MEDIUM mcollina CVE published 2026-10-08

CVE-2026-107298

This PatchSiren debrief is based on the supplied source corpus for CVE-2026-107298, which describes a vulnerability in the msgpack5 package. The vulnerability allows an attacker to exhaust the JavaScript call stack by providing deeply nested MessagePack input, potentially interrupting the process or request handler. The decoder now limits nesting depth to 100 by default and throws 'Maximum decode depth ex [truncated]

MEDIUM mcollina CVE published 2026-10-08

CVE-2026-107297

A remote peer can cause quadratic CPU usage and block the event loop by splitting one valid MessagePack value across many small chunks in the msgpack5 library. The decoder now preserves incremental container state to prevent re-parsing completed elements. Defenders should assess exposure, prioritize remediation, and verify inventory for msgpack5 usage.

LOW mcollina CVE published 2026-10-08

CVE-2026-107296

The msgpack5 package has a vulnerability where decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer. This may cause silently corrupted data in applications that retain or reuse encoded input for integrity checks, logging, or subsequent processing. The issue is caused by the decoder writing to the input buffer when computing signed 64-bit values. Po [truncated]