Stack Exhaustion Vulnerability in StableLib's CBOR Decoder
CVE-2026-106447

8.7HIGH

Key Information:

Vendor

Stablelib

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106447?

The @stablelib/cbor decoder in prior versions of StableLib processes nested CBOR structures without enforcing a maximum recursion limit, which can lead to stack exhaustion. This occurs due to the decoder's ability to continuously process deeply nested structures through the _decodeValue() function, potentially exhausting the JavaScript call stack. As a result, this may cause decoding exceptions, terminating the affected request worker or process unexpectedly. Users are encouraged to update to version 2.0.4 or later, where this issue has been addressed.

Affected Version(s)

stablelib < 2.0.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.