REDHAT-BUG-2453284: Medium severity npm/serialize-javascript vulnerability
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted "array-like" object (an object that inherits from Array.prototype but has a very large length property), the process enters an intensive loop that consumes 100% CPU and hangs indefinitely. This issue has been patched in version 7.0.5.
Affected Software
Event History
Frequently Asked Questions
What input is required to trigger the CPU exhaustion?
The vulnerable serializer must process a specially crafted array-like object that inherits from Array.prototype and has a very large length property. Processing this object causes an intensive loop that can consume 100% CPU and hang indefinitely.
Which deployments are affected?
Deployments using npm/serialize-javascript before version 7.0.5 are affected when they serialize attacker-controlled or otherwise untrusted objects. The provided data does not identify any configuration prerequisite beyond use of a vulnerable version.
What is the remediation?
Update npm/serialize-javascript to version 7.0.5 or later, where the issue is patched.