Where
-Infinity
0

Vendor Risk Score

See how lxsmnsyc compares to other vendors in security performance

View Risk Score →
Severity
7.5
EPSS
0.01%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service).

Mitigation: Seroval introduces disabledFeatures (a bitmask) in serialization/deserialization methods, with Feature.RegExp as a dedicated flag. Users are recommended to configure disabledFeatures to disable RegExp serialization entirely.

1 / 3
Source: GitHub
First published (updated )
Severity
7.5
EPSS
0.01%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Serialization of objects with extreme depth can exceed the maximum call stack limit.

Mitigation: Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

1 / 2
Source: GitHub
First published (updated )
Severity
7.5
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.

Mitigation: Seroval no longer encodes array lengths. Instead, it computes length using Array.prototype.length during deserialization.

1 / 2
Source: GitHub
First published (updated )
Severity
9.8
EPSS
0.05%
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This affects only JSON deserialization functionality.

As there is no known workaround, please upgrade to the latest version.

1 / 2
Source: GitHub
First published (updated )
Severity
7.5
EPSS
0.08%
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution.

The vulnerability can be exploited via overriding constant value and error deserialization, which allows indirect access to unsafe JS evaluation. This requires at least the ability to perform 4 separate requests on the same function and partial knowledge of how the serialized data is used during later runtime processing.

This vulnerability affects the fromJSON and fromCrossJSON functions in a client-to-server transmission scenario.

No known workarounds or mitigations are known, so please upgrade to the patched version.

1 / 2
Source: GitHub
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203