Denial of Service Vulnerability in Seroval by LXSMNSYC
CVE-2026-104845

7.5HIGH

Key Information:

Vendor

Lxsmnsyc

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104845?

Seroval, a library that enables JavaScript value stringification beyond the basic capabilities of JSON.stringify, has a vulnerability that allows an attacker to exploit the deserialization methods, specifically deserializeTypedArray in fromJSON and fromCrossJSON. This vulnerability occurs when the library fails to adequately bound the serialized element count of a deserialized source value treated as an ArrayBuffer. An attacker can provide a maliciously crafted JSON object that claims a large length value, leading to synchronous allocation of excessive memory or CPU resources, ultimately resulting in the exhaustion of system resources and starving the event loop. It's important to note that while there is no identified impact on confidentiality or integrity, this vulnerability can significantly disrupt application performance. The issue has been addressed in version 1.6.3.

Affected Version(s)

seroval < 1.6.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.