VYPR
Vendor

Mcollina

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2026-107302HigOct 8, 2026
    risk 0.42cvss 7.5epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds…

  • CVE-2026-107300HigOct 8, 2026
    risk 0.42cvss 7.5epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small valid values, causing recursion…

  • CVE-2026-107301MedOct 8, 2026
    risk 0.35cvss 6.5epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, constructing msgpack5 with an empty or partial options object disables the default protoAction: 'error' protection. A decoded map containing a __proto__ key can then replace the decoded object's…

  • CVE-2026-107299MedOct 8, 2026
    risk 0.31cvss 5.9epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder treats the reserved MessagePack byte 0xc1 as incomplete input instead of invalid input. When 0xc1 begins a stream, subsequent data remains buffered while the decoder waits…

  • CVE-2026-107297MedOct 8, 2026
    risk 0.31cvss 5.9epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks,…

  • CVE-2026-107298MedOct 8, 2026
    risk 0.27cvss 5.3epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the array and map decoding paths have no nesting-depth limit, allowing an attacker who can provide MessagePack input to submit deeply nested containers that exhaust the JavaScript call stack and…

  • CVE-2026-107296LowOct 8, 2026
    risk 0.17cvss 3.7epss —

    msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, decoding a negative signed 64-bit integer modifies the corresponding bytes in the caller-provided input buffer while computing the value. Applications that retain or reuse encoded input for…