CVE-2026-24006: Seroval affected by Denial of Service via Deeply Nested Objects
Serialization of objects with extreme depth can exceed the maximum call stack limit.
Mitigation: Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.
Other sources
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24006?
CVE-2026-24006 has a severity that can lead to a Denial of Service due to stack overflow from deeply nested objects.
How do I fix CVE-2026-24006?
To fix CVE-2026-24006, upgrade to Seroval version 1.4.1 or later to prevent stack overflow issues.
What versions of Seroval are affected by CVE-2026-24006?
CVE-2026-24006 affects Seroval versions 1.4.0 and below.
What type of vulnerability is CVE-2026-24006?
CVE-2026-24006 is classified as a Denial of Service (DoS) vulnerability.
What triggers the vulnerability in CVE-2026-24006?
The vulnerability in CVE-2026-24006 is triggered by serializing objects with extreme depth, exceeding the maximum call stack limit.