CVE-2026-23956
HIGHseroval <1.4.1 - ReDoS
Title source: llmDescription
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service). This issue has been fixed in version 1.4.1.
Scores
CVSS v3
7.5
EPSS
0.0003
EPSS Percentile
7.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-1333
Status
published
Affected Products (3)
npm/seroval
< 1.4.1npm
lxsmnsyc/seroval
< 1.4.1
lxsmnsyc/seroval
< 1.4.1
Timeline
Published
Jan 22, 2026
Tracked Since
Feb 18, 2026