Intel

AIKIDO-2026-634891

seroval is vulnerable to Denial of Service

Denial of ServiceGHSA-9355-h2pj-8fqj Published 2 days ago

75

High Risk

This Affects:

JSseroval
0.0.1 - 1.6.3
Fixed in 1.6.4
Are you affected? Scan for Free

TL;DR

seroval's JSON deserializers (fromJSON/fromCrossJSON) build typed array and DataView values from a buffer node without checking its type, so a crafted payload can put a number or an array like value in that buffer and select an unexpected TypedArray constructor overload. A request body of about 90 to 142 bytes then makes the deserializer allocate hundreds of megabytes to gigabytes of memory and consume CPU, and in cross mode the oversized buffer stays in the shared refs map across chunks. Any server that passes a body received over HTTP straight into the deserializer is exposed with no other precondition, and applications that also register functions through createReference() can have one of those functions called during the same deserialization. The fix checks that the buffer node is an actual ArrayBuffer before constructing the typed array or view.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

seroval is vulnerable to Denial of Service in versions 0.0.1 - 1.6.3.

How to fix this

Upgrade the seroval library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform