Summary
The decoder accepts input that violates the specification's canonicalization requirements. Specifically, it does not enforce: msgpack-shortest-integer.
Specification
msgpack-shortest-integer: The MessagePack specification directs an encoder to use the shortest representation that holds the value, so a decoder that accepts a wider encoding admits a second encoding of a value its own encoder would never emit.
Source: https://github.com/msgpack/msgpack/blob/master/spec.md
Affected Version
Reproduction
The following hex-encoded byte strings demonstrate the issue. Each should be rejected by a strict decoder but is currently accepted:
Witnesses (should be rejected):
cc6c
ce00000006
Canonical controls (correctly accepted):
9334406d
93376c5a
Detection Method
Decode with the library's public API, re-encode the decoded value with the SAME library's encoder, and compare bytes. The library is its own reference, so no second implementation is needed: accepting bytes its own encoder would never emit is the defect.
Impact
A decoder that admits a non-canonical encoding of a value its own encoder would never produce breaks the one-encoding-per-value property that content addressing and signature verification rely on. No chain-level reachability is claimed here.
Summary
The decoder accepts input that violates the specification's canonicalization requirements. Specifically, it does not enforce: msgpack-shortest-integer.
Specification
msgpack-shortest-integer: The MessagePack specification directs an encoder to use the shortest representation that holds the value, so a decoder that accepts a wider encoding admits a second encoding of a value its own encoder would never emit.
Source: https://github.com/msgpack/msgpack/blob/master/spec.md
Affected Version
Reproduction
The following hex-encoded byte strings demonstrate the issue. Each should be rejected by a strict decoder but is currently accepted:
Witnesses (should be rejected):
cc6c
ce00000006
Canonical controls (correctly accepted):
9334406d
93376c5a
Detection Method
Decode with the library's public API, re-encode the decoded value with the SAME library's encoder, and compare bytes. The library is its own reference, so no second implementation is needed: accepting bytes its own encoder would never emit is the defect.
Impact
A decoder that admits a non-canonical encoding of a value its own encoder would never produce breaks the one-encoding-per-value property that content addressing and signature verification rely on. No chain-level reachability is claimed here.