HIGH7.5
GHSA-hx9m-jf43-8ffr
seroval affected by Denial of Service via RegExp serialization
Quick fix
GHSA-hx9m-jf43-8ffr — seroval: upgrade to the fixed version with the command below.
npm install seroval@1.4.1Details
Overriding RegExp serialization with extremely large patterns can **exhaust JavaScript runtime memory** during deserialization. Additionally, overriding RegExp serialization with patterns that trigger **catastrophic backtracking** can lead to ReDoS (Regular Expression Denial of Service).
**Mitigation**: `Seroval` introduces `disabledFeatures` (a bitmask) in serialization/deserialization methods, with `Feature.RegExp` as a dedicated flag. **Users are recommended to configure `disabledFeatures` to disable RegExp serialization entirely.**
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-hx9m-jf43-8ffr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23956[ADVISORY]
- https://github.com/lxsmnsyc/seroval/commit/ce9408ebc87312fcad345a73c172212f2a798060[WEB]
- https://github.com/lxsmnsyc/seroval[PACKAGE]
- https://github.com/lxsmnsyc/seroval/blob/v0.2.0/packages/seroval/src/index.ts#L90[WEB]