CVE-2026-23957
HIGHseroval < 1.4.1 - Denial of Service via Array Length Manipulation
Title source: llmDescription
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time. This issue has been fixed in version 1.4.1.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-66fc-rw6m-c2q6
Scores
CVSS v3
7.5
EPSS
0.0040
EPSS Percentile
31.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (2)
lxsmnsyc/seroval
< 1.4.1 (2 CPE variants)
npm/seroval
0 - 1.4.1npm
Published
Jan 22, 2026
Tracked Since
Feb 18, 2026