Release notes
v6.1.0
This release hardens decoding of malformed and adversarial MessagePack input, improves streaming performance, and adds optional collection-size limits.
Security fixes
- GHSA-8F34-F56X-9XPH: Handle truncated
map32headers as incomplete input. - GHSA-5X5G-H9X8-2FH9: Drain concatenated streaming values iteratively to avoid stack overflows.
- GHSA-26WQ-P25C-J6FV: Reject the reserved MessagePack byte and release buffered input on stream errors.
- GHSA-8HQ7-GGX2-CC6M: Preserve prototype protection when callers provide partial options and validate
protoAction. - GHSA-24CH-F2G6-9HHH: Limit decoder nesting depth to prevent stack exhaustion.
- GHSA-GCX5-HXJ7-GPQQ: Decode streaming containers incrementally to avoid repeated work on incomplete input.
- GHSA-QW35-55VC-RHJG: Decode signed 64-bit integers without mutating caller-owned buffers.
Other changes
- Add optional
maxArrayLengthandmaxMapLengthdecoder limits.