CVE-2026-106447
CVE-2026-106447 is a high-severity vulnerability with a CVSS 4.0 base score of 8.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-674.
Key facts
- Severity: High (CVSS 4.0 base score 8.7)
- EPSS exploit prediction: 0% (29th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-674
- Published:
- Last modified:
Description
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
Frequently asked questions
- What is CVE-2026-106447?
- StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. A sufficiently deep structure exhausts the JavaScript call stack, causing a decoding exception and potentially terminating an uncaught request worker or process. This issue is fixed in version 2.0.4.
- How severe is CVE-2026-106447?
- CVE-2026-106447 has a CVSS 4.0 base score of 8.7, rated high severity.
- Is CVE-2026-106447 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (29th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-106447?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-106447 published?
- CVE-2026-106447 was published on 2026-10-06 and last updated on 2026-10-07.
References
- https://github.com/StableLib/stablelib/commit/0149e18d9d4736e22c257744ca945ebce7899a01
- https://github.com/StableLib/stablelib/releases/tag/@stablelib/[email protected]
- https://github.com/StableLib/stablelib/security/advisories/GHSA-5jg4-p4qw-cgfr
Other CWE-674 (Uncontrolled Recursion) vulnerabilities
- CVE-2026-43185 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in…
- CVE-2023-51803 — Critical (CVSS 9.8): LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>"…
- CVE-2021-41752 — Critical (CVSS 9.8): Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due…
- CVE-2018-1000618 — Critical (CVSS 9.8): EOSIO/eos eos version after commit f1545dd0ae2b77580c2236fdb70ae7138d2c7168 contains a stack overflow vulnerability in…
- CVE-2025-10728 — Critical (CVSS 9.4): When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading…
- CVE-2026-32327 — Critical (CVSS 9.1): A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses…
Browse all CWE-674 (Uncontrolled Recursion) vulnerabilities →