Executive brief
Seroval is a JavaScript serialization library used to convert objects to and from a serialized format. An attacker can send maliciously crafted serialized data with excessively large array length values, causing the deserialization process to consume excessive CPU and time, leading to a denial of service that degrades application performance or availability.
Technical details
The vulnerability is a denial-of-service flaw rooted in inadequate input validation during array deserialization (CWE-770). The vulnerable code encodes array lengths in the serialized data without proper bounds checking. An attacker can override these length fields with extremely large values, forcing the deserialization routine to allocate memory and perform processing for an inflated array size, causing the application to hang or become unresponsive. The vulnerability requires no authentication and is reachable over the network if Seroval is used to deserialize untrusted input. The fix, available in version 1.4.1 and later, removes the explicit array length encoding and instead computes the length from Array.prototype.length during deserialization, eliminating the attack surface.
Affected products
- <UNKNOWN> Seroval <=1.4.0
Timeline
- 2026-01-21: disclosed
- 2026-01-21: patched: Version 1.4.1 released with fix