{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amsgpack5_projectmsgpack5node.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:msgpack5_project:msgpack5:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-107302"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["msgpack5 (\u003c 6.1.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe msgpack5 library is susceptible to a denial-of-service vulnerability (CVE-2026-107302) affecting versions prior to 6.1.0. The flaw resides in the decoding logic for 'map32' structures. When the library receives a truncated map32 header (specifically identified by the 0xdf type prefix) that provides fewer than the required five bytes, the internal decoder fails to throw the expected 'IncompleteBufferError'. Instead, the decoder initiates an out-of-bounds buffer read, resulting in a 'RangeError'. This inconsistency disrupts stream and request processing in dependent applications, which typically rely on catching 'IncompleteBufferError' to safely wait for additional data. While the vulnerability does not lead to arbitrary code execution or disclosure of adjacent memory due to underlying buffer implementation checks, it enables a remote attacker to crash specific services or terminate active worker processes by injecting malformed data payloads.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects any application using msgpack5 \u0026lt; 6.1.0 to deserialize message pack data from untrusted network sources. Successful exploitation results in the abrupt termination of application processes or request handlers, causing a denial-of-service condition. This impact is significant for high-throughput messaging or API services that process serialized payloads, as these services are often critical components of distributed architectures.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the msgpack5 package to version 6.1.0 or later to ensure proper validation of map32 headers.\u003c/li\u003e\n\u003cli\u003eImplement upstream validation for input buffers if immediate patching is not possible; ensure at least five bytes are present for payloads starting with the 0xdf prefix.\u003c/li\u003e\n\u003cli\u003eApply defensive coding in application-level error handlers to catch 'RangeError' for logic flows utilizing msgpack5, treating it as an incomplete input signal until the library is patched.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:26:29Z","date_published":"2026-10-08T19:26:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-msgpack5-range-error/","summary":"An out-of-bounds buffer read in msgpack5 versions prior to 6.1.0 (CVE-2026-107302) triggers an unhandled RangeError when encountering truncated map32 headers, leading to potential application-level denial of service.","title":"msgpack5 Truncated map32 Header Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-10-msgpack5-range-error/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:msgpack5_project:msgpack5:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}