Disclosure summary
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for integrity checks, logging, or later processing can observe silently corrupted data, while positive integers and other MessagePack value types are unaffected. This issue is fixed in version 6.1.0.
Source-reported weakness categories
CWE-471
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107296
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-qw35-55vc-rhgj
Open original source · Updated Oct 08, 2026
msgpack5: Decoding negative int64 values mutates the input buffer
Source severity: LOW / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | msgpack5 | < 6.1.0 | 6.1.0 |
Original records & references
PUBLISHED 2026-10-08T13:17:15-04:00
MODIFIED 2026-10-08T16:48:36-04:00
INGESTED 2026-10-10T20:55:03-04:00