CVE-2026-102360
Received Received - Intake

Memory Corruption in lib0 Binary Decoder

Vulnerability report for CVE-2026-102360, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens**, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dmonad lib0 to 0.2.118 (exc)
dmonad lib0 to 1.0.0-rc.33 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing bounds check in the lib0 library's binary decoder function readUint8Array. It allows unauthenticated remote attackers to read adjacent process memory by supplying an over-long length prefix. The decoder does not validate the input length against its own buffer size, causing it to return memory outside the intended data range. This can expose sensitive data like other users' document content, personal information, or session tokens.

Detection Guidance

To detect this vulnerability, check if your system uses vulnerable versions of lib0 (0.2.1-0.2.117 or 1.0.0-rc.32). Run commands like 'npm list lib0' or 'grep lib0 package-lock.json' to verify installed versions. If affected, update to patched versions (0.2.118 or 1.0.0-rc.33).

Monitor network traffic for unusual data exfiltration or memory leaks in applications using lib0. Inspect logs for errors related to 'readUint8Array' or buffer overflows.

Impact Analysis

An attacker could exploit this to read sensitive data from the memory of systems using vulnerable lib0 versions. If the system echoes, stores, or re-serves decoded values, the attacker can recover and access adjacent memory contents. This includes cross-tenant data leaks, theft of credentials, and exposure of personal or session data. The impact is high due to the potential for unauthorized data access without authentication.

Compliance Impact

This vulnerability can lead to unauthorized access and exposure of personal data, violating GDPR's principles of data protection and user privacy. For HIPAA, it risks exposing protected health information, leading to compliance breaches. Organizations using vulnerable lib0 versions may face legal penalties, reputational damage, and mandatory breach notifications under these regulations.

Mitigation Strategies

Immediately update lib0 to versions 0.2.118 or 1.0.0-rc.33 or later. If updating is not possible, restrict network access to lib0-based services until patched. Review and audit applications using lib0 for potential memory exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102360. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart