Vulnerability GHSA-8f34-f56x-9xph

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 hours ago
October 08, 2026 at 05:40 PM UTC
msgpack5: Truncated map32 headers throw an unexpected error
1.0.0 - 6.0.2
1.0.0 - 6.0.2

Summary

msgpack5: Truncated map32 headers throw an unexpected error

Details

Impact

A truncated map32 header causes an out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError. Applications that rely on IncompleteBufferError to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds.

Patches

The decoder now validates the complete five-byte map32 header before reading its length and reports truncated input as IncompleteBufferError.

Workarounds

Require at least five bytes before decoding a value beginning with 0xdf, or catch RangeError and treat it as incomplete input only for truncated map32 headers.

Impacted packages

Timeline

Published
5 hours ago
October 08, 2026 at 05:40 PM UTC
Fixed (6.1.0)
Unknown
Unknown
Last Modified
5 hours ago
October 08, 2026 at 06:00 PM UTC