VDB
Sign up
HIGH7.5

GHSA-3j22-8qj3-26mx

Seroval affected by Denial of Service via Deeply Nested Objects

Quick fix

GHSA-3j22-8qj3-26mx — seroval: upgrade to the fixed version with the command below.

npm install seroval@1.4.1

Details

Serialization of objects with extreme depth can **exceed the maximum call stack limit**.

**Mitigation**: `Seroval` introduces a `depthLimit` parameter in serialization/deserialization methods. **An error will be thrown if the depth limit is reached.**

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/seroval
Introduced in: 0Fixed in: 1.4.1
Fixnpm install seroval@1.4.1

References