Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray constructor to synchronously allocate the selected number of elements and exhaust CPU or memory while starving the event loop. The offset check does not reject the crafted source because source.byteLength is undefined. DataView reaches a similar unchecked cast but throws rather than allocating, and the issue has no identified confidentiality or integrity impact. This issue is fixed in version 1.6.3.
Published: 2026-10-02
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Memory Exhaustion / Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability allows an attacker to trigger memory exhaustion by supplying a JSON payload that contains a TypedArray constructor call with an exaggerated length. Before version 1.6.3 the Seroval library deserializes the length value without any bounds checking and immediately allocates a TypedArray of that size synchronously, consuming CPU and memory and starving the JavaScript event loop. The code assumes a valid ArrayBuffer and bypasses an offset check, allowing the crafted length to be accepted. This flaw results in a denial‑of‑service condition; there is no impact on confidentiality or integrity.

Affected Systems

The affected product is the JavaScript library Seroval maintained by lxsmnsyc. Any installation of Seroval prior to version 1.6.3 that processes user‑supplied JSON is vulnerable.

Risk and Exploitability

The flaw has a CVSS score of 7.5, indicating a high severity. EPSS is not available, but the lack of any imposed limit on the array length makes opportunistic exploitation plausible. The vulnerability is not listed in CISA’s KEV catalog, yet it presents a DoS vector that could disrupt any service relying on Seroval. An attacker can exploit the issue remotely by sending a carefully crafted JSON payload that triggers synchronous allocation of a large array, exhausting host resources.

Generated by OpenCVE AI on October 2, 2026 at 17:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Seroval library to version 1.6.3 or later, which implements bounds checking on TypedArray lengths.
  • If an upgrade is not immediately possible, validate any JSON data before deserialization and enforce a maximum allowed length for TypedArray constructions.
  • Monitor application performance and memory usage for sudden spikes, and log deserialization attempts to detect abusive payloads.

Generated by OpenCVE AI on October 2, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Lxsmnsyc
Lxsmnsyc seroval
Vendors & Products Lxsmnsyc
Lxsmnsyc seroval

Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray constructor to synchronously allocate the selected number of elements and exhaust CPU or memory while starving the event loop. The offset check does not reject the crafted source because source.byteLength is undefined. DataView reaches a similar unchecked cast but throws rather than allocating, and the issue has no identified confidentiality or integrity impact. This issue is fixed in version 1.6.3.
Title Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Lxsmnsyc Seroval
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T15:55:21.197Z

Reserved: 2026-10-02T14:38:43.243Z

Link: CVE-2026-104845

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:47.070

Modified: 2026-10-02T16:16:47.200

Link: CVE-2026-104845

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling