seroval is vulnerable to Denial of Service
75
High Risk
seroval's JSON deserializers (fromJSON/fromCrossJSON) build typed array and DataView values from a buffer node without checking its type, so a crafted payload can put a number or an array like value in that buffer and select an unexpected TypedArray constructor overload. A request body of about 90 to 142 bytes then makes the deserializer allocate hundreds of megabytes to gigabytes of memory and consume CPU, and in cross mode the oversized buffer stays in the shared refs map across chunks. Any server that passes a body received over HTTP straight into the deserializer is exposed with no other precondition, and applications that also register functions through createReference() can have one of those functions called during the same deserialization. The fix checks that the buffer node is an actual ArrayBuffer before constructing the typed array or view.
You are affected if you are using a version that falls within the vulnerable range.
seroval is vulnerable to Denial of Service in versions 0.0.1 - 1.6.3.
Upgrade the seroval library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.