HIGH 7.5 npm

Seroval affected by Denial of Service via Deeply Nested Objects

GHSA-3j22-8qj3-26mx · CVE-2026-24006

Published · Modified

Description

Serialization of objects with extreme depth can exceed the maximum call stack limit.

Mitigation:
Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

Ready to move

Start Securing

Free, no credit card | First findings in minutes