Impact
A bounds check was omitted in lib0’s binary decoder, allowing the readUint8Array function to read beyond the provided buffer. An unauthenticated peer can send a length prefix that exceeds the actual data size, causing the decoder to return memory that follows the buffer. This leakage can expose other users’ document content, personal data and even live bearer session tokens. The flaw is an out‑of‑bounds read and therefore constitutes a memory disclosure that compromises confidentiality.
Affected Systems
The vulnerability exists in the dmonad:lib0 library. All releases up to 0.2.117 and 1.0.0‑rc.32 inclusive are affected. Versions 0.2.118 and 1.0.0‑rc.33 and later contain the fix.
Risk and Exploitability
The CVSS v3.1 score is 8.6, indicating high severity. EPSS data are not available, so the exact exploitation probability is unknown, but the lack of bounds checking and the ability to exploit it before authentication make it a high‑risk vulnerability. The flaw is listed in no KEV catalog. An attacker can trigger it simply by connecting to a lib0 instance and sending malformed data over the network, resulting in arbitrary memory disclosure.
OpenCVE Enrichment