Description
fido2-lib v3.x depends on cbor-x (~1.6.0), which optionally pulls in cbor-extract (C++ native addon). cbor-extract <= 2.2.0 has a heap buffer over-read in extractStrings() — a 5-byte CBOR payload crashes Node.js with SIGSEGV. No JS exception, no try/catch, process dead.
Recommendation
Update the fido2-lib package to the latest compatible version. Followings are version details:
- Affected version(s): <= 3.5.7
- Patched version(s): 3.5.8
References
Could your website be exposed too?
SmartScanner can check your website for fido2-lib is vulnerable to DoS via cbor-extract heap buffer over-read in CBOR attestation parsing and gives you actionable findings to investigate.
Start a free scanRelated Issues
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
- Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString() - Vulnerability
- Cube Core is vulnerable to Denial of Service (DoS) via crafted request - CVE-2026-25957
- Nuxt OG Image vulnerable to Server-Side Request Forgery via user-controlled parameters - Vulnerability


