Vulnerability GHSA-3j22-8qj3-26mx

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
January 22, 2026 at 06:02 PM UTC
Seroval affected by Denial of Service via Deeply Nested Objects
0.1.0 - 1.4.0
0.1.0 - 1.4.0

Summary

Seroval affected by Denial of Service via Deeply Nested Objects

Details

Serialization of objects with extreme depth can exceed the maximum call stack limit.

Mitigation:
Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

Impacted packages

Timeline

Published
8 months ago
January 22, 2026 at 06:02 PM UTC
Fixed (1.4.1)
9 months ago
December 19, 2025 at 11:25 PM UTC
Last Modified
8 months ago
February 03, 2026 at 03:10 AM UTC