HIGH 7.5 npm

Seroval affected by Denial of Service via Array serialization

GHSA-66fc-rw6m-c2q6 · CVE-2026-23957

Published · Modified

Description

Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.

Mitigation:
Seroval no longer encodes array lengths.
Instead, it computes length using Array.prototype.length during deserialization.

Ready to move

Start Securing

Free, no credit card | First findings in minutes