Sceawere
Vulnerability Detail
CVE-2026-102521UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Out-of-Bounds Read in lib0
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.6
- Creation Date
- 11h ago
- Vendor
- dmonad
- Product
- lib0
- Attack Type
- CWE-125: Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. The vulnerability allows reading past the decoders' view, thus exposing adjacent process memory. This can be anything that is currently in the head, for example credentials or logs. This is similar to but different from GHSA-r5c8-rf4w-qrq8.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.6",
"pubDate": "2026-09-29T14:17:20.393Z",
"pubdate": "2026-09-29T14:17:20.393Z",
"executiveSummary": "The library lib0 is susceptible to an out-of-bounds (OOB) read vulnerability located within the readFromDataView decoder function. This vulnerability, affecting versions prior to 0.2.119, arises from improper bounds validation during data decoding operations.\nBy manipulating the input provided to the decoder, an attacker can coerce the library into reading memory addresses residing outside the allocated boundaries of the intended buffer. This flaw enables the unauthorized disclosure of sensitive data stored in the process's heap, which may include security-sensitive information such as authentication credentials, session tokens, or application logs.\nThe risk is significant as it facilitates unauthorized information disclosure without requiring authentication or specific user privileges. The exploitation of this vulnerability relies on an attacker's ability to supply malformed input that bypasses the decoder's intended access controls, effectively broadening the attack surface to the adjacent memory space of the host process.",
"technicalDetails": "The vulnerability resides in the readFromDataView function of the lib0 library. The root cause is a deficiency in the boundary verification logic performed during the decoding of binary data from a DataView object. Specifically, the decoder fails to correctly validate the length of the requested read operation against the actual length of the underlying buffer.\nIn a typical attack flow, an adversary provides a crafted input payload to the application that utilizes lib0. By exploiting the logic error in readFromDataView, the attacker sends a request that triggers a read operation specifying an offset and length that extend beyond the allocated buffer boundaries. Because the decoder does not implement strict bounds checking, it processes the request as legitimate, accessing contiguous memory addresses immediately following the legitimate buffer within the process heap.\nThe vulnerability acts as an OOB read primitive, allowing the attacker to read arbitrary data from adjacent memory segments. The post-exploitation impact includes the potential for full information disclosure. Since the memory heap often contains transient data such as cryptographic keys, user credentials, or sensitive application state, the exposure of this 'adjacent' memory can lead to full system compromise or session hijacking, depending on the nature of the application and the content residing in the heap at the time of the exploit.\nThis issue is identified as a logic flaw in handling data buffers, similar to, yet distinct from, the vulnerabilities documented under GHSA-r5c8-rf4w-qrq8. It affects all versions of the lib0 package preceding 0.2.119. Exploitation does not require high-level privileges, as the vulnerability is inherent to the library's internal decoding logic and can be leveraged by any entity capable of influencing the input processed by the library. The attack is effective in any environment where an attacker can provide input that is subsequently processed by an unpatched lib0 decoder."
}