<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:msgpack5_project:msgpack5:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amsgpack5_projectmsgpack5node.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 19:26:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amsgpack5_projectmsgpack5node.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>msgpack5 Truncated map32 Header Denial of Service</title><link>https://feed.craftedsignal.io/briefs/2026-10-msgpack5-range-error/</link><pubDate>Thu, 08 Oct 2026 19:26:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-msgpack5-range-error/</guid><description>An out-of-bounds buffer read in msgpack5 versions prior to 6.1.0 (CVE-2026-107302) triggers an unhandled RangeError when encountering truncated map32 headers, leading to potential application-level denial of service.</description><content:encoded><![CDATA[<p>The msgpack5 library is susceptible to a denial-of-service vulnerability (CVE-2026-107302) affecting versions prior to 6.1.0. The flaw resides in the decoding logic for 'map32' structures. When the library receives a truncated map32 header (specifically identified by the 0xdf type prefix) that provides fewer than the required five bytes, the internal decoder fails to throw the expected 'IncompleteBufferError'. Instead, the decoder initiates an out-of-bounds buffer read, resulting in a 'RangeError'. This inconsistency disrupts stream and request processing in dependent applications, which typically rely on catching 'IncompleteBufferError' to safely wait for additional data. While the vulnerability does not lead to arbitrary code execution or disclosure of adjacent memory due to underlying buffer implementation checks, it enables a remote attacker to crash specific services or terminate active worker processes by injecting malformed data payloads.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects any application using msgpack5 &lt; 6.1.0 to deserialize message pack data from untrusted network sources. Successful exploitation results in the abrupt termination of application processes or request handlers, causing a denial-of-service condition. This impact is significant for high-throughput messaging or API services that process serialized payloads, as these services are often critical components of distributed architectures.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the msgpack5 package to version 6.1.0 or later to ensure proper validation of map32 headers.</li>
<li>Implement upstream validation for input buffers if immediate patching is not possible; ensure at least five bytes are present for payloads starting with the 0xdf prefix.</li>
<li>Apply defensive coding in application-level error handlers to catch 'RangeError' for logic flows utilizing msgpack5, treating it as an incomplete input signal until the library is patched.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>