Vulnerability GHSA-8f34-f56x-9xph
Summary
msgpack5: Truncated map32 headers throw an unexpected error
Details
Impact
A truncated map32 header causes an out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError. Applications that rely on IncompleteBufferError to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds.
Patches
The decoder now validates the complete five-byte map32 header before reading its length and reports truncated input as IncompleteBufferError.
Workarounds
Require at least five bytes before decoding a value beginning with 0xdf, or catch RangeError and treat it as incomplete input only for truncated map32 headers.
Related Vulnerabilities
Other vulnerabilities affecting the same packages