Vulnerability GHSA-gcx5-hxj7-gpqq

Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 hours ago
October 08, 2026 at 05:39 PM UTC
msgpack5: Quadratic parsing in the streaming decoder
1.0.0 - 6.0.2
1.0.0 - 6.0.2

Summary

msgpack5: Quadratic parsing in the streaming decoder

Details

Impact

The streaming decoder reparses an incomplete container from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack value across many small chunks, causing quadratic CPU usage and blocking the event loop.

Patches

The decoder now preserves incremental container state so completed elements are not parsed again when more input arrives.

Workarounds

Buffer each complete MessagePack value before decoding it, or limit the number of chunks accepted for a single value.

Impacted packages

Timeline

Published
5 hours ago
October 08, 2026 at 05:39 PM UTC
Fixed (6.1.0)
Unknown
Unknown
Last Modified
5 hours ago
October 08, 2026 at 06:00 PM UTC