CVE-2026-107299

CVE-2026-107299 published: msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered wh...

View full NVD advisory → ← Back to CVE watch