CVE-2026-106447: StableLib: Stack exhaustion denial of service via deeply nested CBOR arrays, maps, or tags
Published Oct 6, 2026
·Updated
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
Affected Software
1 affected component
npm/@stablelib/cbor<2.0.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@stablelib/cborto a version that resolves this vulnerability.Fixed in 2.0.4
Event History
Oct 6, 2026
CVE Published
via MITRE·07:44 PM
Data Sourced
via MITRE·07:44 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness