CVE WATCH / VULNERABILITY DETAIL
CVE-2026-107297
MEDIUMCVSS 5.9NVD feed
Published 8 October 2026 · tracked since 9 October 2026
Description
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elemen
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107294 MEDIUM 6.5
- CVE-2026-107295 HIGH 7.6
- CVE-2026-107296 LOW 3.7
- CVE-2026-107290 MEDIUM 6.5
- CVE-2026-107291
- CVE-2026-107292 MEDIUM 6.4
- CVE-2026-107293
- CVE-2026-105436 HIGH 8.8
- CVE-2026-104077 HIGH 7.8
- CVE-2026-107288 LOW 3.7