Vulnerability DatabaseCVE-2026-106447

CVE-2026-106447: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-106447 is a stack exhaustion denial-of-service vulnerability in the @stablelib/cbor decoder, a component of the StableLib TypeScript/JavaScript library. The decoder recursively processes nested CBOR arrays, maps, and tags via _decodeValue() without enforcing any maximum nesting depth, allowing a crafted payload to exhaust the JavaScript call stack. All versions prior to 2.0.4 are affected. The vulnerability was disclosed on April 2, 2026, and assigned a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is CWE-674 (Uncontrolled Recursion): the _decodeValue() function in @stablelib/cbor descends recursively into each nested CBOR container — arrays, maps, and tagged values — without any depth counter or iterative fallback (GitHub Advisory). An attacker can craft a payload consisting of thousands of nested single-element arrays (e.g., [[[...[null]...]]]), encoded as a sequence of 0x81 bytes followed by 0xf6 (null), to force the decoder to recurse until a RangeError: Maximum call stack size exceeded is thrown. The attack requires no authentication, no special privileges, and no user interaction — only the ability to supply CBOR data to an application using the vulnerable library. A proof-of-concept is included in the public advisory (GitHub Advisory).

Impact

Successful exploitation causes a RangeError exception during CBOR decoding, which can crash the request worker or terminate the Node.js process if the exception is not caught. The impact is limited to availability — there is no confidentiality or integrity impact, and no lateral movement potential is associated with this vulnerability. Any internet-facing service that accepts and decodes attacker-controlled CBOR data using @stablelib/cbor versions prior to 2.0.4 is at risk of reliable, repeatable denial of service with a single small crafted payload (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept is publicly available in the GitHub security advisory itself, demonstrating that a ~12,001-byte payload of nested arrays is sufficient to trigger the crash (GitHub Advisory). There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting low current exploitation probability (Feedly). The attack is unauthenticated, requires no privileges, and is network-accessible, making it straightforward to execute against exposed services.

Exploitation steps

  1. Identify target: Locate a service that accepts CBOR-encoded data over the network and uses @stablelib/cbor version ≤ 2.0.1 for decoding (e.g., via API endpoint inspection, npm dependency scanning, or package.json disclosure).
  2. Craft malicious payload: Construct a deeply nested CBOR array payload. Using the published PoC, create a Uint8Array of length 12,001: fill the first 12,000 bytes with 0x81 (CBOR array(1)) and set the last byte to 0xf6 (CBOR null), producing [[[...[null]...]]] nested 12,000 levels deep.
  3. Transmit payload: Send the crafted CBOR payload to the target endpoint via HTTP POST (or the appropriate transport), setting the Content-Type header to application/cbor or the format expected by the service.
  4. Trigger stack exhaustion: The decoder's _decodeValue() function recurses 12,000 times, exhausting the JavaScript call stack and throwing RangeError: Maximum call stack size exceeded.
  5. Achieve denial of service: If the application does not catch the exception, the request worker or process terminates, causing service disruption. Repeating the request prevents recovery until the service is restarted or patched (GitHub Advisory).

Indicators of compromise

  • Network: Repeated inbound requests to CBOR-consuming API endpoints with payloads of approximately 12,001 bytes consisting predominantly of the byte 0x81; unusual spikes in request volume to CBOR endpoints followed by service crashes.
  • Logs: Application error logs showing RangeError: Maximum call stack size exceeded originating from @stablelib/cbor decode calls; worker process crash or restart events in process manager logs (e.g., PM2, systemd).
  • Process: Unexpected termination or restart of Node.js worker processes handling CBOR decoding; increased process restart frequency logged by the process supervisor.

Mitigation and workarounds

Upgrade @stablelib/cbor to version 2.0.4 or later, which enforces a default maximum nesting depth of 128 and introduces a configurable maxDepth option (GitHub Release, GitHub Commit). The fix also introduces typed error classes (e.g., CBORMaxDepthExceededError) to allow applications to catch and handle depth violations gracefully. As a short-term workaround prior to upgrading, wrap all decode() calls in try/catch blocks to prevent uncaught exceptions from crashing workers, and consider validating or rejecting unusually large CBOR payloads at the network or application layer (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106448HIGH8.9
  • JavaScript logoJavaScript
  • @stablelib/cbor
NoYesOct 06, 2026
CVE-2026-106447HIGH8.7
  • JavaScript logoJavaScript
  • @stablelib/cbor
NoYesOct 06, 2026
CVE-2026-105854HIGH8.7
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026
CVE-2026-105855HIGH7.6
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026
CVE-2026-105853HIGH7.1
  • JavaScript logoJavaScript
  • payload
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management