PT-2026-102609 · Lib0 · Lib0

·

CVE-2026-102360

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions lib0 versions 0.2.1 through 0.2.117 lib0 versions prior to 1.0.0-rc.33
Description A missing bounds check in the binary decoder allows an unauthenticated remote peer to read adjacent process memory. The readUint8Array() function fails to compare the length supplied over the wire against the decoder's own view. Consequently, providing an over-long length prefix can result in the disclosure of data allocated next by the host process, such as personal data, document content from other tenants, and live bearer session tokens. This occurs when an attacker supplies bytes to a lib0 decoder via an open socket, and the consumer echoes, stores, or re-serves the decoded value.
Recommendations Update to version 0.2.118. Update to version 1.0.0-rc.33.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102360
GHSA-R5C8-RF4W-QRQ8

Affected Products

Lib0