Vulnerability GHSA-3j22-8qj3-26mx
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
January 22, 2026 at 06:02 PM UTC
Seroval affected by Denial of Service via Deeply Nested Objects
0.1.0 - 1.4.0
0.1.0 - 1.4.0
Summary
Seroval affected by Denial of Service via Deeply Nested Objects
Details
Serialization of objects with extreme depth can exceed the maximum call stack limit.
Mitigation:
Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
8 hours ago
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
0.12.0 - 1.6.1 GHSA-p6vx-979v-rg4c
0.12.0 - 1.6.1 GHSA-p6vx-979v-rg4c
High Risk
8 hours ago
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
0.1.0 - 1.6.2 GHSA-jp82-f5mq-hwhp
0.1.0 - 1.6.2 GHSA-jp82-f5mq-hwhp
Critical
2 months ago
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
0.1.0 - 1.5.2 GHSA-mv8w-475r-vwqw
0.1.0 - 1.5.2 GHSA-mv8w-475r-vwqw
High Risk
8 months ago
Seroval affected by Denial of Service via Array serialization
0.1.0 - 1.4.0 GHSA-66fc-rw6m-c2q6
0.1.0 - 1.4.0 GHSA-66fc-rw6m-c2q6
High Risk
8 months ago
seroval affected by Denial of Service via RegExp serialization
0.2.0 - 1.4.0 GHSA-hx9m-jf43-8ffr
0.2.0 - 1.4.0 GHSA-hx9m-jf43-8ffr
Impacted packages
Timeline
Published
8 months ago
January 22, 2026 at 06:02 PM UTC
Fixed (1.4.1)
9 months ago
December 19, 2025 at 11:25 PM UTC
Last Modified
8 months ago
February 03, 2026 at 03:10 AM UTC