Executive brief
msgpackr is a JavaScript library for encoding and decoding MessagePack data, a compact binary message format used in applications for efficient data serialization. A flaw in how the library converts property names to strings can be exploited by an attacker sending specially crafted messages to cause threads to hang indefinitely, leading to denial of service and application unavailability.
Technical details
The vulnerability is an infinite recursion bug (CWE-674) in msgpackr's property name conversion logic that occurs during MessagePack decoding. When a user supplies malicious MessagePack messages with recursive references (particularly involving the 0x70 extension type for structured cloning), the decoder becomes stuck in a loop attempting to convert property names to strings, causing the decoding thread to hang indefinitely. The attack requires network access to send crafted messages to an application using msgpackr, with no authentication or user interaction needed. An attacker can trigger a denial of service by exhausting available threads. The fix is available in version 1.10.1; prior versions are affected. A temporary workaround is to replace the 0x70 extension handler to prevent recursive referencing.
Affected products
- msgpackr msgpackr < 1.10.1
Timeline
- 2023-12-28: disclosed: GHSA advisory published