CVE-2026-24006

HIGH

Seroval <1.4.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

Scores

CVSS v3 7.5
EPSS 0.0003
EPSS Percentile 8.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
lxsmnsyc/seroval < 1.4.1 (2 CPE variants)
npm/seroval 0 - 1.4.1npm
Published Jan 22, 2026
Tracked Since Feb 18, 2026