Denial of Service Vulnerability in Seroval by LXSMNSYC
CVE-2026-104845
What is CVE-2026-104845?
Seroval, a library that enables JavaScript value stringification beyond the basic capabilities of JSON.stringify, has a vulnerability that allows an attacker to exploit the deserialization methods, specifically deserializeTypedArray in fromJSON and fromCrossJSON. This vulnerability occurs when the library fails to adequately bound the serialized element count of a deserialized source value treated as an ArrayBuffer. An attacker can provide a maliciously crafted JSON object that claims a large length value, leading to synchronous allocation of excessive memory or CPU resources, ultimately resulting in the exhaustion of system resources and starving the event loop. It's important to note that while there is no identified impact on confidentiality or integrity, this vulnerability can significantly disrupt application performance. The issue has been addressed in version 1.6.3.
Affected Version(s)
seroval < 1.6.3
