CVE-2026-23957: seroval is vulnerable to Denial of Service via array serialization
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.
Mitigation: Seroval no longer encodes array lengths. Instead, it computes length using Array.prototype.length during deserialization.
Other sources
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time. This issue has been fixed in version 1.4.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23957?
CVE-2026-23957 has a high severity due to its potential to cause Denial of Service by significantly increasing processing times.
How do I fix CVE-2026-23957?
To fix CVE-2026-23957, update the seroval package to version 1.4.1 or later, as this version no longer encodes array lengths.
What type of vulnerability is CVE-2026-23957?
CVE-2026-23957 is a Denial of Service vulnerability that arises from array serialization issues in the seroval package.
Which versions of seroval are affected by CVE-2026-23957?
Versions of seroval up to and including 1.4.0 are affected by CVE-2026-23957.
Can CVE-2026-23957 impact application performance?
Yes, CVE-2026-23957 can severely impact application performance by causing significant delays during deserialization.