{"id":"CVE-2026-102360","summary":"lib0 `readUint8Array` performs an unbounded read past the end of the decoder’s view, disclosing adjacent process memory","details":"A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens**, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.","aliases":["GHSA-r5c8-rf4w-qrq8"],"modified":"2026-10-02T03:31:03.261922475Z","published":"2026-09-29T13:11:55.735Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102360.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"last_affected":"0.2.1-0.2.117"}]}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102360.json"},{"type":"ADVISORY","url":"https://github.com/dmonad/lib0/security/advisories/GHSA-r5c8-rf4w-qrq8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102360"},{"type":"FIX","url":"https://github.com/dmonad/lib0/commit/425f28dc82c8df1b6f7e1ab20ea1a0a15a3c355f"},{"type":"FIX","url":"https://github.com/dmonad/lib0/commit/c4c9db0b41346a33aff31a51f1f09c3a17757f10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dmonad/lib0","events":[{"introduced":"0"},{"fixed":"425f28dc82c8df1b6f7e1ab20ea1a0a15a3c355f"},{"fixed":"c4c9db0b41346a33aff31a51f1f09c3a17757f10"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.0-rc.32"}]}}],"versions":["v0.2.117","v1.0.0-rc.32","v1.0.0-rc.31","v1.0.0-rc.30","v1.0.0-rc.29","v1.0.0-rc.28","v1.0.0-rc.27","v1.0.0-rc.26","v1.0.0-rc.23","v1.0.0-rc.22","v1.0.0-rc.21","v1.0.0-rc.20","v1.0.0-rc.19","v1.0.0-rc.18","v1.0.0-rc.17","v1.0.0-rc.16","v1.0.0-rc.15","v1.0.0-rc.14","v1.0.0-rc.13","v1.0.0-rc.12","v1.0.0-rc.11","v1.0.0-rc.10","v1.0.0-rc.9","v1.0.0-rc.8","v1.0.0-rc.7","v1.0.0-rc.6","v1.0.0-rc.5","v1.0.0-rc.4","v1.0.0-rc.3","v1.0.0-rc.2","v1.0.0-rc.1","v1.0.0-rc.0","v1.0.0-0","v0.2.116","v0.2.115","v0.2.115-6","v0.2.115-5","v0.2.115-4","v0.2.115-3","v0.2.115-2","v0.2.115-1","v0.2.115-0","v0.2.114","v0.2.112","v0.2.111","v0.2.110","v0.2.109","v0.2.108","v0.2.107","v0.2.106","v0.2.105","v0.2.104","v0.2.103","v0.2.102","v0.2.101","v0.2.100","v0.2.99","v0.2.98","v0.2.97","v0.2.96","v0.2.95","v0.2.94","v0.2.93","v0.2.92","v0.2.91","v0.2.90","v0.2.89","v0.2.88","v0.2.87","v0.2.86","v0.2.85","v0.2.84","v0.2.83","v0.2.82","v0.2.81","v0.2.80","v0.2.79","v0.2.78","v0.2.77","v0.2.76","v0.2.75","v0.2.74","v0.2.73","v0.2.72","v0.2.71","v0.2.70","v0.2.69","v0.2.68","v0.2.67","v0.2.66","v0.2.65","v0.2.64","v0.2.63","v0.2.62","v0.2.61","v0.2.60","v0.2.59","v0.2.58","v0.2.57","v0.2.56","v0.2.55","v0.2.54","v0.2.53","v0.2.52","v0.2.51","v0.2.50","v0.2.49","v0.2.48","v0.2.47","v0.2.46","v0.2.45","v0.2.44","v0.2.43","v0.2.42","v0.2.41","v0.2.40","v0.2.39","v0.2.38","v0.2.37","v0.2.36","v0.2.35","v0.2.34","v0.2.33","v0.2.32","v0.2.31","v0.2.30","v0.2.29","v0.2.28","v0.2.27","v0.2.26","v0.2.25","v0.2.24","v0.2.23","v0.2.22","v0.2.21","v0.2.20","v0.2.19","v0.2.18","v0.2.17","v0.2.14","v0.2.13","v0.2.12","v0.2.11","v0.2.10","v0.2.9","v0.2.8","v0.2.7","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.7","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.1","v0.1.0","v0.0.6","v0.0.5","v0.0.4","v0.0.3","v0.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102360.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}