CVE-2026-106447EPSS p29.1%
CVE-2026-106447CVE-2026-106447
Description
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
Scoring
| EPSS | 0.37% probability of exploitation · percentile 29.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |