HIGH7.5
GHSA-66fc-rw6m-c2q6
Seroval affected by Denial of Service via Array serialization
Quick fix
GHSA-66fc-rw6m-c2q6 — seroval: upgrade to the fixed version with the command below.
npm install seroval@1.4.1Details
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to **significantly increase processing time**.
**Mitigation**: `Seroval` no longer encodes array lengths. Instead, it computes length using `Array.prototype.length` during deserialization.
Are you affected?
Enter the version of the package you're using.