Intel

AIKIDO-2026-270573

lib0 is vulnerable to Out-of-Bounds Read

Out-of-Bounds ReadCVE-2026-102360 Published Yesterday

86

High Risk

This Affects:

JSlib0
0.1.0 - 0.2.117
Fixed in 0.2.118
Are you affected? Scan for Free

TL;DR

lib0's binary decoder readUint8Array builds a Uint8Array view sized directly from a peer-supplied length prefix, without checking it against the bytes remaining in the decoder's buffer. Because small Node Buffers are views into a shared 64 KiB allocation slab, an over-long length returns whatever adjacent data the process allocated next, including other connections' messages, tenant data, or session tokens. readVarUint8Array and readVarString inherit the same missing check. The fix rejects negative or out-of-range lengths before constructing the view.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

lib0 is vulnerable to Out-of-Bounds Read in versions 0.1.0 - 0.2.117.

How to fix this

Upgrade the lib0 library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform