FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Decoder accepts non-minimal encoding · Issue #297 · msgpack/msgpack-javascript · GitHub

Repository navigation

Decoder accepts non-minimal encoding #297

Description

Summary

The decoder accepts input that violates the specification's canonicalization requirements. Specifically, it does not enforce: msgpack-shortest-integer.

Specification

msgpack-shortest-integer: The MessagePack specification directs an encoder to use the shortest representation that holds the value, so a decoder that accepts a wider encoding admits a second encoding of a value its own encoder would never emit.

Source: https://github.com/msgpack/msgpack/blob/master/spec.md

Affected Version

  • @msgpack/msgpack 3.1.3

Reproduction

The following hex-encoded byte strings demonstrate the issue. Each should be rejected by a strict decoder but is currently accepted:

Witnesses (should be rejected):

cc6c
ce00000006

Canonical controls (correctly accepted):

9334406d
93376c5a

Detection Method

Decode with the library's public API, re-encode the decoded value with the SAME library's encoder, and compare bytes. The library is its own reference, so no second implementation is needed: accepting bytes its own encoder would never emit is the defect.

Impact

A decoder that admits a non-canonical encoding of a value its own encoder would never produce breaks the one-encoding-per-value property that content addressing and signature verification rely on. No chain-level reachability is claimed here.

Activity

  1. trackoor commented on Sep 26, 2026

    Author

    Filed by mistake; duplicate of #296. Sorry for the noise.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL