Vulnerability GHSA-jp82-f5mq-hwhp

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
7 hours ago
October 05, 2026 at 11:40 PM UTC
Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
0.1.0 - 1.6.2
0.1.0 - 1.6.2

Summary

Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization

Details

Summary

deserializeTypedArray casts the source node to ArrayBuffer without checking it and never bounds the element count. Pass a plain object with a length property and it hits the array-like TypedArray constructor, allocating that many elements. The offset guard above it can't stop this: source.byteLength is undefined, so the comparison is always false.

The length is one integer in the JSON, so a tiny payload can name any allocation size, and it runs synchronously inside fromJSON, starving the event loop instead of just slowing one request. fromCrossJSON is the same.

Impact is unauthenticated CPU/memory exhaustion for any service deserializing untrusted Seroval JSON: same profile as the array-length and nested-depth DoS issues already fixed here. No confidentiality or integrity impact. DataView has the same unchecked cast but throws instead of allocating. A runtime instanceof ArrayBuffer check plus a size cap should fix it.

Impacted packages

Timeline

Published
7 hours ago
October 05, 2026 at 11:40 PM UTC
Fixed (1.6.3)
1 month ago
August 22, 2026 at 06:14 PM UTC
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC