{"api_version":"1","generated_at":"2026-10-08T21:45:49+00:00","cve":"CVE-2026-107297","urls":{"html":"https://cve.report/CVE-2026-107297","api":"https://cve.report/api/cve/CVE-2026-107297.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107297","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107297"},"summary":{"title":"msgpack5: Quadratic parsing in the streaming decoder","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-08 17:17:15","updated_at":"2026-10-08 20:48:36"},"problem_types":["CWE-407","CWE-407 CWE-407: Inefficient Algorithmic Complexity"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq","name":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","name":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4","name":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107297","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107297","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"mcollina","product":"msgpack5","version":"affected < 6.1.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-107297","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-08T17:26:19.427864Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-08T17:26:27.457Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"msgpack5","vendor":"mcollina","versions":[{"status":"affected","version":"< 6.1.0"}]}],"descriptions":[{"lang":"en","value":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-407","description":"CWE-407: Inefficient Algorithmic Complexity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T17:07:03.740Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-gcx5-hxj7-gpqq"},{"name":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4","tags":["x_refsource_MISC"],"url":"https://github.com/mcollina/msgpack5/commit/e4827641d3105e295cbbd56e9c5389978547eab4"},{"name":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","tags":["x_refsource_MISC"],"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0"}],"source":{"advisory":"GHSA-gcx5-hxj7-gpqq","discovery":"UNKNOWN"},"title":"msgpack5: Quadratic parsing in the streaming decoder"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-107297","datePublished":"2026-10-08T17:07:03.740Z","dateReserved":"2026-10-07T15:53:23.587Z","dateUpdated":"2026-10-08T17:26:27.457Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 17:17:15","lastModifiedDate":"2026-10-08 20:48:36","problem_types":["CWE-407","CWE-407 CWE-407: Inefficient Algorithmic Complexity"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-08T17:26:19.427864Z","id":"CVE-2026-107297","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107297","Ordinal":"1","Title":"msgpack5: Quadratic parsing in the streaming decoder","CVE":"CVE-2026-107297","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107297","Ordinal":"1","NoteData":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.","Type":"Description","Title":"msgpack5: Quadratic parsing in the streaming decoder"}]}}}