High severityNVD Advisory· Published Oct 6, 2026
CVE-2026-106447
CVE-2026-106447
Description
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
Affected products
1- Range: <2.0.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.