CVE-2026-107302

CVE-2026-107302 published: msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a check...

View full NVD advisory → ← Back to CVE watch