@stablelib/cbor
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @stablelib/cborpage 1 of 1
- CVE-2026-106447HIGHCVSS 8.7EG 8.7fixed in 2.0.32026-10-06
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor decoder recursively processes nested CBOR arrays, maps, and tags through _decodeValue() without enforcing a maximum nesting depth. …
- CVE-2026-106448HIGHCVSS 8.9EG 8.9fixed in 2.0.32026-10-06
StableLib is a stable library of useful TypeScript and JavaScript code. Prior to 2.0.4, the @stablelib/cbor CBOR map decoding path creates ordinary JavaScript objects and assigns attacker-controlled keys with bracket assignment. A map key …
Check whether @stablelib/cbor is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @stablelib/cbor CVEs against the assets you own.
Book a Demo →