
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-106447 is a stack exhaustion denial-of-service vulnerability in the @stablelib/cbor decoder, a component of the StableLib TypeScript/JavaScript library. The decoder recursively processes nested CBOR arrays, maps, and tags via _decodeValue() without enforcing any maximum nesting depth, allowing a crafted payload to exhaust the JavaScript call stack. All versions prior to 2.0.4 are affected. The vulnerability was disclosed on April 2, 2026, and assigned a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Feedly).
The root cause is CWE-674 (Uncontrolled Recursion): the _decodeValue() function in @stablelib/cbor descends recursively into each nested CBOR container — arrays, maps, and tagged values — without any depth counter or iterative fallback (GitHub Advisory). An attacker can craft a payload consisting of thousands of nested single-element arrays (e.g., [[[...[null]...]]]), encoded as a sequence of 0x81 bytes followed by 0xf6 (null), to force the decoder to recurse until a RangeError: Maximum call stack size exceeded is thrown. The attack requires no authentication, no special privileges, and no user interaction — only the ability to supply CBOR data to an application using the vulnerable library. A proof-of-concept is included in the public advisory (GitHub Advisory).
Successful exploitation causes a RangeError exception during CBOR decoding, which can crash the request worker or terminate the Node.js process if the exception is not caught. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement potential is associated with this vulnerability. Any internet-facing service that accepts and decodes attacker-controlled CBOR data using @stablelib/cbor versions prior to 2.0.4 is at risk of reliable, repeatable denial of service with a single small crafted payload (GitHub Advisory, Feedly).
A proof-of-concept is publicly available in the GitHub security advisory itself, demonstrating that a ~12,001-byte payload of nested arrays is sufficient to trigger the crash (GitHub Advisory). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting low current exploitation probability (Feedly). The attack is unauthenticated, requires no privileges, and is network-accessible, making it straightforward to execute against exposed services.
@stablelib/cbor version ≤ 2.0.1 for decoding (e.g., via API endpoint inspection, npm dependency scanning, or package.json disclosure).Uint8Array of length 12,001: fill the first 12,000 bytes with 0x81 (CBOR array(1)) and set the last byte to 0xf6 (CBOR null), producing [[[...[null]...]]] nested 12,000 levels deep.Content-Type header to application/cbor or the format expected by the service._decodeValue() function recurses 12,000 times, exhausting the JavaScript call stack and throwing RangeError: Maximum call stack size exceeded.0x81; unusual spikes in request volume to CBOR endpoints followed by service crashes.RangeError: Maximum call stack size exceeded originating from @stablelib/cbor decode calls; worker process crash or restart events in process manager logs (e.g., PM2, systemd).Upgrade @stablelib/cbor to version 2.0.4 or later, which enforces a default maximum nesting depth of 128 and introduces a configurable maxDepth option (GitHub Release, GitHub Commit). The fix also introduces typed error classes (e.g., CBORMaxDepthExceededError) to allow applications to catch and handle depth violations gracefully. As a short-term workaround prior to upgrading, wrap all decode() calls in try/catch blocks to prevent uncaught exceptions from crashing workers, and consider validating or rejecting unusually large CBOR payloads at the network or application layer (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."