seroval 1.6.7 appears to be a healthy dependency: it has a long release history with 87 releases, 18 releases in the last 12 months, a stable non-prerelease version, active recent repository work, six active contributors, and no deprecation or archival indicators. The package is MIT licensed, typed, dependency-free at runtime, and backed by a matching repository with tests, changelog material, security policy, automated security scanning, and restrictive workflow permissions. The main reservations are the absence of build provenance attestation and concentration of recent commits in one contributor, although the other five active contributors and ongoing release activity reduce the abandonment concern.
92%
Total Score
75
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-476182 seroval is vulnerable to Deserialization of Untrusted Data in versions 0.13.0 - 1.5.2. | 0.13.0 - 1.5.2 | Critical |
CVE-2026-24006 seroval is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | High |
CVE-2026-23957 seroval is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.0 - 1.4.0. | 0.0.0 - 1.4.0 | High |
CVE-2026-23956 seroval is vulnerable to Inefficient Regular Expression Complexity in versions 0.2.0 - 1.4.0. | 0.2.0 - 1.4.0 | High |
CVE-2026-23737 seroval is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.4.1. | 0.0.0 - 1.4.1 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.