Backport msgpack fix for CVE-2026-57585 to vendored msgpack - #127
Merged
Merged
Conversation
Reusing an Unpacker after a failed unpack resumed from a corrupt parser context and could crash the process. Port upstream msgpack-python commit 2c56ddb: unpack_clear now releases the whole stack and re-initialises the context, unpack_construct/unpack_skip clear on failure, Unpacker._unpack clears before raising, and map_key is reset once consumed. Closes #124. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 27, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes CVE-2026-57585 (GHSA-6v7p-g79w-8964) in the vendored msgpack: reusing an
Unpackerafter a failed unpack resumed from a corrupt parser context and could crash the process.This ports upstream msgpack-python commit
2c56ddbintosrsly/msgpack/unpack_template.hand_unpacker.pyx. The fork's callbacks have the same reference-ownership semantics as upstream, so the patch applies as-is:unpack_clearreleases every stack entry (including pending map keys) and re-initialises the contextunpack_construct/unpack_skipclear the context when they failUnpacker._unpackclears the context before raisingmap_keyis reset oncemap_itemhas consumed itBehaviour only changes after an error, when an
Unpackernow resumes from a clean state. The high-level helpers (srsly.msgpack_loadsetc.) create a fresh unpacker per call and are unaffected.Tests: upstream's regression tests are added as new test functions, and no existing tests are changed. Without the fix,
test_unpacker_should_not_crash_after_exceptionkills the interpreter andtest_unpacker_usable_after_exceptionfails.Closes #124.
馃 Generated with Claude Code