Vulnerability GHSA-66fc-rw6m-c2q6

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
January 21, 2026 at 05:05 PM UTC
Seroval affected by Denial of Service via Array serialization
0.1.0 - 1.4.0
0.1.0 - 1.4.0

Summary

Seroval affected by Denial of Service via Array serialization

Details

Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.

Mitigation:
Seroval no longer encodes array lengths. Instead, it computes length using Array.prototype.length during deserialization.

Impacted packages

Timeline

Published
8 months ago
January 21, 2026 at 05:05 PM UTC
Fixed (1.4.1)
9 months ago
December 19, 2025 at 11:25 PM UTC
Last Modified
8 months ago
February 03, 2026 at 03:10 AM UTC