CVE-2026-106447
StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, maps, or tags
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
| CWE | CWE-674 |
| Vendor | stablelib |
| Product | stablelib |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for stablelib stablelib
Be the first to know when new unknown vulnerabilities affecting stablelib stablelib are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
StableLib / stablelib
< 2.0.4