Sceawere
Vulnerability Detail
CVE-2026-102360UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
lib0 Out-of-Bounds Memory Read
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 11h ago
- Vendor
- dmonad
- Product
- lib0
- Attack Type
- CWE-125: Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens**, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-09-29T14:17:20.117Z",
"pubdate": "2026-09-29T14:17:20.117Z",
"executiveSummary": "A critical out-of-bounds read vulnerability exists in the lib0 library due to a missing bounds check within its binary decoder component.\nThis vulnerability impacts versions 0.2.1-0.2.117 and 1.0.0-rc.32 and earlier, affecting systems that utilize lib0 for decoding wire-formatted binary data.\nThe flaw allows an unauthenticated remote attacker to read arbitrary memory adjacent to the decoder's buffer, potentially exfiltrating sensitive data such as document content, personal identifiable information, and active session tokens.\nExploitation is possible for any remote peer capable of establishing a socket connection, even prior to formal application-level authentication.\nThe risk is severe as it enables memory disclosure that can be leveraged to compromise other tenants' data or hijack active sessions if the application echoes or stores the malformed decoded output.\nThe lack of validation on length prefixes provided in the wire-format allows the attacker to manipulate the memory read operation directly.",
"technicalDetails": "The root cause of this vulnerability is a missing bounds validation logic within the `readUint8Array` function of the lib0 binary decoder. When processing wire-formatted data, the decoder fails to verify the length prefix specified in the incoming data stream against the actual bounds of the allocated buffer maintained by the decoder.\nDuring the decoding process, the `readUint8Array` function interprets a length field provided by the remote peer to determine the size of the array to read. Because there is no comparison performed between this supplied length and the decoder's own view of the buffer, the function proceeds to read memory beyond the allocated range.\nAn attacker can exploit this by crafting a malicious binary payload where the length prefix for an array is significantly larger than the available data provided in the buffer. Upon processing this malicious payload, the decoder will continue to read bytes from the process memory that are contiguous to the allocated buffer until the attacker-specified length is satisfied.\nThis effectively grants the attacker read access to arbitrary contiguous memory locations in the host process's address space. The exfiltrated data may contain sensitive information currently residing in the heap, including live session tokens, private document fragments, or other tenants' data in multi-tenant environments.\nThe attack flow requires an adversary to establish a network connection, such as a socket connection, to the service utilizing the vulnerable lib0 library. The attacker transmits the malformed binary stream containing the oversized length prefix. If the application logic echoes, stores, or re-serves the resultant decoded value back to the sender or another endpoint, the attacker can successfully recover the leaked memory content.\nAffected versions include 0.2.1 through 0.2.117 and 1.0.0-rc.32 and earlier. This vulnerability does not require authentication to trigger, as the processing occurs during the initial stages of socket communication. Consequently, any network-exposed service implementing these lib0 versions is inherently susceptible to memory disclosure attacks. Post-exploitation, the attacker may utilize recovered bearer tokens to impersonate legitimate users or gain unauthorized access to sensitive application functionality, depending on the nature of the leaked tokens."
}