Vulnerability GHSA-66fc-rw6m-c2q6
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
January 21, 2026 at 05:05 PM UTC
Seroval affected by Denial of Service via Array serialization
0.1.0 - 1.4.0
0.1.0 - 1.4.0
Summary
Seroval affected by Denial of Service via Array serialization
Details
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.
Mitigation:
Seroval no longer encodes array lengths. Instead, it computes length using Array.prototype.length during deserialization.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
8 hours ago
Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
0.12.0 - 1.6.1 GHSA-p6vx-979v-rg4c
0.12.0 - 1.6.1 GHSA-p6vx-979v-rg4c
High Risk
8 hours ago
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
0.1.0 - 1.6.2 GHSA-jp82-f5mq-hwhp
0.1.0 - 1.6.2 GHSA-jp82-f5mq-hwhp
Critical
2 months ago
seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization
0.1.0 - 1.5.2 GHSA-mv8w-475r-vwqw
0.1.0 - 1.5.2 GHSA-mv8w-475r-vwqw
High Risk
8 months ago
Seroval affected by Denial of Service via Deeply Nested Objects
0.1.0 - 1.4.0 GHSA-3j22-8qj3-26mx
0.1.0 - 1.4.0 GHSA-3j22-8qj3-26mx
High Risk
8 months ago
seroval affected by Denial of Service via RegExp serialization
0.2.0 - 1.4.0 GHSA-hx9m-jf43-8ffr
0.2.0 - 1.4.0 GHSA-hx9m-jf43-8ffr
Impacted packages
Timeline
Published
8 months ago
January 21, 2026 at 05:05 PM UTC
Fixed (1.4.1)
9 months ago
December 19, 2025 at 11:25 PM UTC
Last Modified
8 months ago
February 03, 2026 at 03:10 AM UTC