Junglewise Threat Intelligence

CVE-2026-23957: Seroval denial of service via array serialization

CVE-2026-23957 · Severity: low · CVSS 3.1 · Published 2026-01-21

Technologies: seroval (npm). Vendors: Unknown, npm.

Executive brief

Seroval is a JavaScript serialization library used to convert objects to and from a serialized format. An attacker can send maliciously crafted serialized data with excessively large array length values, causing the deserialization process to consume excessive CPU and time, leading to a denial of service that degrades application performance or availability.

Technical details

The vulnerability is a denial-of-service flaw rooted in inadequate input validation during array deserialization (CWE-770). The vulnerable code encodes array lengths in the serialized data without proper bounds checking. An attacker can override these length fields with extremely large values, forcing the deserialization routine to allocate memory and perform processing for an inflated array size, causing the application to hang or become unresponsive. The vulnerability requires no authentication and is reachable over the network if Seroval is used to deserialize untrusted input. The fix, available in version 1.4.1 and later, removes the explicit array length encoding and instead computes the length from Array.prototype.length during deserialization, eliminating the attack surface.

Affected products

  • <UNKNOWN> Seroval <=1.4.0

Timeline

  • 2026-01-21: disclosed
  • 2026-01-21: patched: Version 1.4.1 released with fix

References

Related threats