lib0 is vulnerable to Out-of-Bounds Read
86
High Risk
lib0's binary decoder readUint8Array builds a Uint8Array view sized directly from a peer-supplied length prefix, without checking it against the bytes remaining in the decoder's buffer. Because small Node Buffers are views into a shared 64 KiB allocation slab, an over-long length returns whatever adjacent data the process allocated next, including other connections' messages, tenant data, or session tokens. readVarUint8Array and readVarString inherit the same missing check. The fix rejects negative or out-of-range lengths before constructing the view.
You are affected if you are using a version that falls within the vulnerable range.
lib0 is vulnerable to Out-of-Bounds Read in versions 0.1.0 - 0.2.117.
Upgrade the lib0 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.