Vulnerability GHSA-gcx5-hxj7-gpqq
Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 hours ago
October 08, 2026 at 05:39 PM UTC
msgpack5: Quadratic parsing in the streaming decoder
1.0.0 - 6.0.2
1.0.0 - 6.0.2
Summary
msgpack5: Quadratic parsing in the streaming decoder
Details
Impact
The streaming decoder reparses an incomplete container from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack value across many small chunks, causing quadratic CPU usage and blocking the event loop.
Patches
The decoder now preserves incremental container state so completed elements are not parsed again when more input arrives.
Workarounds
Buffer each complete MessagePack value before decoding it, or limit the number of chunks accepted for a single value.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
5 hours ago
msgpack5: Truncated map32 headers throw an unexpected error
1.0.0 - 6.0.2 GHSA-8f34-f56x-9xph
1.0.0 - 6.0.2 GHSA-8f34-f56x-9xph
Medium Risk
5 hours ago
msgpack5: Deeply nested input can exhaust the decoder stack
1.0.0 - 6.0.2 GHSA-24ch-f2g6-9hhh
1.0.0 - 6.0.2 GHSA-24ch-f2g6-9hhh
Low Risk
5 hours ago
msgpack5: Decoding negative int64 values mutates the input buffer
1.0.0 - 6.0.2 GHSA-qw35-55vc-rhgj
1.0.0 - 6.0.2 GHSA-qw35-55vc-rhgj
Medium Risk
5 years ago
Prototype poisoning
1.0.0 - 3.6.0 and 4.0.0 - 4.5.0 and 5.0.0 - 5.2.0 GHSA-gmjw-49p4-pcfm
1.0.0 - 3.6.0 and 4.0.0 - 4.5.0 and 5.0.0 - 5.2.0 GHSA-gmjw-49p4-pcfm
Impacted packages
Timeline
Published
5 hours ago
October 08, 2026 at 05:39 PM UTC
Fixed (6.1.0)
Unknown
Unknown
Last Modified
5 hours ago
October 08, 2026 at 06:00 PM UTC