Description
A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens**, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.
Published: 2026-09-29
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote Memory Disclosure
Action: Apply Patch
AI Analysis

Impact

A bounds check was omitted in lib0’s binary decoder, allowing the readUint8Array function to read beyond the provided buffer. An unauthenticated peer can send a length prefix that exceeds the actual data size, causing the decoder to return memory that follows the buffer. This leakage can expose other users’ document content, personal data and even live bearer session tokens. The flaw is an out‑of‑bounds read and therefore constitutes a memory disclosure that compromises confidentiality.

Affected Systems

The vulnerability exists in the dmonad:lib0 library. All releases up to 0.2.117 and 1.0.0‑rc.32 inclusive are affected. Versions 0.2.118 and 1.0.0‑rc.33 and later contain the fix.

Risk and Exploitability

The CVSS v3.1 score is 8.6, indicating high severity. EPSS data are not available, so the exact exploitation probability is unknown, but the lack of bounds checking and the ability to exploit it before authentication make it a high‑risk vulnerability. The flaw is listed in no KEV catalog. An attacker can trigger it simply by connecting to a lib0 instance and sending malformed data over the network, resulting in arbitrary memory disclosure.

Generated by OpenCVE AI on September 29, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade lib0 to version 0.2.118 or later, or 1.0.0‑rc.33 or later; the patch removes the out‑of‑bounds read.
  • Regenerate or retire any bearer tokens or session credentials that may have been exposed through the leak.
  • Block unauthenticated peers from sending data to the decoder until the library is updated, for example by enforcing an authentication handshake before deserialization.

Generated by OpenCVE AI on September 29, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens**, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.
Title lib0 `readUint8Array` performs an unbounded read past the end of the decoder’s view, disclosing adjacent process memory
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-29T13:55:21.424Z

Reserved: 2026-09-28T22:38:42.255Z

Link: CVE-2026-102360

cve-icon Vulnrichment

Updated: 2026-09-29T13:55:16.782Z

cve-icon NVD

Status : Received

Published: 2026-09-29T14:17:20.117

Modified: 2026-09-29T14:17:20.117

Link: CVE-2026-102360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T15:15:14Z

Weaknesses