HIGH 7.5 npm
Seroval affected by Denial of Service via Array serialization
GHSA-66fc-rw6m-c2q6 · CVE-2026-23957
Published · Modified
Description
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.
Mitigation:Seroval no longer encodes array lengths.
Instead, it computes length using Array.prototype.length during deserialization.
Ready to move
Start Securing
Free, no credit card | First findings in minutes