CVE-2026-102360: lib0 `readUint8Array` performs an unbounded read past the end of the decoder’s view, disclosing adjacent process memory
A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. readUint8Array never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
lib0to a version that resolves this vulnerability.Fixed in 0.2.118 - Upgrade
Upgrade
lib0to a version that resolves this vulnerability.Fixed in 1.0.0-rc.33
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated exploitation?
Any deployment where a remote peer can supply bytes to a lib0 decoder is exposed, including peers that can open a socket before authentication. The vulnerable decoder can return adjacent process memory when it processes an over-long length prefix.
Which versions should be upgraded?
Upgrade lib0 to 0.2.118 or later on the 0.2.x line, or to 1.0.0-rc.33 or later on the 1.0.0 release-candidate line. Versions 0.2.1 through 0.2.117 and earlier, and 1.0.0-rc.32 and earlier, are affected.
What must happen for leaked memory to reach an attacker?
The attacker must be able to send a crafted binary value with a length larger than the decoder view. The decoded value must then be echoed, stored, or re-served by the consuming application for the attacker to receive the out-of-bounds data.