VDB
Sign up
HIGH7.5

GHSA-66fc-rw6m-c2q6

Seroval affected by Denial of Service via Array serialization

Quick fix

GHSA-66fc-rw6m-c2q6 — seroval: upgrade to the fixed version with the command below.

npm install seroval@1.4.1

Details

Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to **significantly increase processing time**.

**Mitigation**: `Seroval` no longer encodes array lengths. Instead, it computes length using `Array.prototype.length` during deserialization.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/seroval
Introduced in: 0Fixed in: 1.4.1
Fixnpm install seroval@1.4.1

References