{"api_version":"1","generated_at":"2026-10-08T21:46:03+00:00","cve":"CVE-2026-107300","urls":{"html":"https://cve.report/CVE-2026-107300","api":"https://cve.report/api/cve/CVE-2026-107300.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107300","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107300"},"summary":{"title":"msgpack5: Many buffered values can exhaust the streaming decoder stack","description":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-10-08 17:17:16","updated_at":"2026-10-08 20:48:36"},"problem_types":["CWE-674","CWE-674 CWE-674: Uncontrolled Recursion"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba","name":"https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","name":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9","name":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107300","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107300","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"mcollina","product":"msgpack5","version":"affected < 6.1.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-107300","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-08T17:52:32.790652Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-08T17:52:48.010Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"msgpack5","vendor":"mcollina","versions":[{"status":"affected","version":"< 6.1.0"}]}],"descriptions":[{"lang":"en","value":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-674","description":"CWE-674: Uncontrolled Recursion","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-08T17:11:13.552Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mcollina/msgpack5/security/advisories/GHSA-5x5g-h9x8-2fh9"},{"name":"https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba","tags":["x_refsource_MISC"],"url":"https://github.com/mcollina/msgpack5/commit/77fbef144d05def5d16fc22c37caa64c0a7efeba"},{"name":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0","tags":["x_refsource_MISC"],"url":"https://github.com/mcollina/msgpack5/releases/tag/v6.1.0"}],"source":{"advisory":"GHSA-5x5g-h9x8-2fh9","discovery":"UNKNOWN"},"title":"msgpack5: Many buffered values can exhaust the streaming decoder stack"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-107300","datePublished":"2026-10-08T17:11:13.552Z","dateReserved":"2026-10-07T15:53:23.587Z","dateUpdated":"2026-10-08T17:52:48.010Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-08 17:17:16","lastModifiedDate":"2026-10-08 20:48:36","problem_types":["CWE-674","CWE-674 CWE-674: Uncontrolled Recursion"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-08T17:52:32.790652Z","id":"CVE-2026-107300","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107300","Ordinal":"1","Title":"msgpack5: Many buffered values can exhaust the streaming decoder","CVE":"CVE-2026-107300","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107300","Ordinal":"1","NoteData":"msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion proportional to the value count, exhausting the JavaScript call stack, and interrupting the process or stream. This issue is fixed in version 6.1.0.","Type":"Description","Title":"msgpack5: Many buffered values can exhaust the streaming decoder"}]}}}