๐Ÿ” CVE Alert

CVE-2026-106447

UNKNOWN 0.0

StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, maps, or tags

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.

CWE CWE-674
Vendor stablelib
Product stablelib
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for stablelib stablelib

Be the first to know when new unknown vulnerabilities affecting stablelib stablelib are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

StableLib / stablelib
< 2.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/StableLib/stablelib/security/advisories/GHSA-5jg4-p4qw-cgfr github.com: https://github.com/StableLib/stablelib/commit/0149e18d9d4736e22c257744ca945ebce7899a01 github.com: https://github.com/StableLib/stablelib/releases/tag/@stablelib/[email protected]