VDB
Sign up
HIGH7.5

GHSA-hx9m-jf43-8ffr

seroval affected by Denial of Service via RegExp serialization

Quick fix

GHSA-hx9m-jf43-8ffr — seroval: upgrade to the fixed version with the command below.

npm install seroval@1.4.1

Details

Overriding RegExp serialization with extremely large patterns can **exhaust JavaScript runtime memory** during deserialization. Additionally, overriding RegExp serialization with patterns that trigger **catastrophic backtracking** can lead to ReDoS (Regular Expression Denial of Service).

**Mitigation**: `Seroval` introduces `disabledFeatures` (a bitmask) in serialization/deserialization methods, with `Feature.RegExp` as a dedicated flag. **Users are recommended to configure `disabledFeatures` to disable RegExp serialization entirely.**

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/seroval
Introduced in: 0.2.0Fixed in: 1.4.1
Fixnpm install seroval@1.4.1

References