Junglewise Threat Intelligence

StableLib @stablelib/cbor stack exhaustion denial of service

Severity: medium · CVSS 4 · Published 2026-04-04

Vendors: npm.

Executive brief

@stablelib/cbor is a TypeScript/JavaScript library for encoding and decoding CBOR (Concise Binary Object Representation) data. A vulnerability in the decoder allows an attacker to crash applications by sending specially crafted CBOR payloads with deeply nested arrays, maps, or tags, causing the decoder to exhaust the JavaScript call stack and terminate the process.

Technical details

The vulnerability is an uncontrolled recursion (CWE-674) in the CBOR decoder implementation. The decoder processes arrays, maps, and tagged values through recursive calls to _decodeValue(), with no maximum nesting depth limit. An attacker can supply a payload consisting of thousands of nested structures to force the decoder to recurse until the JavaScript call stack is exhausted, resulting in a RangeError. The attack requires network access to an application that decodes attacker-controlled CBOR data, with no authentication or user interaction required. Services that do not catch the resulting exception safely may terminate the worker or process handling the decode, leading to reliable denial of service. The vulnerability was fixed in version 2.0.4 by introducing a configurable maximum depth limit (default 128) and a CBORMaxDepthExceededError exception type.

Affected products

  • StableLib @stablelib/cbor <2.0.4

Timeline

  • 2026-04-04: disclosed: Advisory GHSA-5jg4-p4qw-cgfr published
  • 2026-04-02: patched: Fix committed to repository; version 2.0.4 released with depth limit enforcement

References

Related threats