Description


msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and interrupt a process, worker, or request handler. This issue is fixed in version 6.1.0.

Related CPE's


Could not find any relations

Weaknesses



CWE-674

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T17:17:15.703Z

15 hours ago

Last modified

2026-10-08T20:48:36.970Z

12 hours ago