---
id: CVE-2026-102521
title: >-
  The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into
  reading more than it should from a buffer
summary: >-
  The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into
  reading more than it should from a buffer. The vulnerability allows reading
  past the decoders' view, thus exposing adjacent process memory. This can be
  anything…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-125
vendor: dmonad
product: lib0
affected:
  - lib0 <= 0.2.118
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:17:20.393'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102521'
references:
  - url: >-
      https://github.com/dmonad/lib0/commit/49383f2716283b90059dbfe01e110c0ab7ef5592
    label: security-advisories@github.com
  - url: 'https://github.com/dmonad/lib0/security/advisories/GHSA-g75x-89c3-rvmr'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T13:34:31.683Z'
---

## Overview

The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. The vulnerability allows reading past the decoders' view, thus exposing adjacent process memory. This can be anything that is currently in the head, for example credentials or logs. This is similar to but different from GHSA-r5c8-rf4w-qrq8.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
