---
id: CVE-2026-102360
title: >-
  A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117
  and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer
  read adjacent process memory and receive it back
summary: >-
  A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117
  and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer
  read adjacent process memory and receive it back. `readUint8Array` never
  compares …
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-125
vendor: dmonad
product: lib0
affected:
  - lib0 <= 0.2.1-0.2.117
  - lib0 <= 1.0.0-rc.32
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:17:20.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102360'
references:
  - url: >-
      https://github.com/dmonad/lib0/commit/425f28dc82c8df1b6f7e1ab20ea1a0a15a3c355f
    label: security-advisories@github.com
  - url: >-
      https://github.com/dmonad/lib0/commit/c4c9db0b41346a33aff31a51f1f09c3a17757f10
    label: security-advisories@github.com
  - url: 'https://github.com/dmonad/lib0/security/advisories/GHSA-r5c8-rf4w-qrq8'
    label: security-advisories@github.com
  - url: 'https://github.com/dmonad/lib0/security/advisories/GHSA-r5c8-rf4w-qrq8'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-29T13:54:57.965828Z'
ingestedAt: '2026-09-29T13:34:31.684Z'
---

## Overview

A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document content, personal data, and live bearer session tokens**, recovered in full and at will. An attacker who can supply bytes to a lib0 decoder which means any peer that can open a socket, including before authentication reads adjacent process memory and, where the consumer echoes, stores or re-serves the decoded value, receives it back. This is patched in version 0.2.118 and 1.0.0-rc.33.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
