Impact
The vulnerability allows an attacker to trigger memory exhaustion by supplying a JSON payload that contains a TypedArray constructor call with an exaggerated length. Before version 1.6.3 the Seroval library deserializes the length value without any bounds checking and immediately allocates a TypedArray of that size synchronously, consuming CPU and memory and starving the JavaScript event loop. The code assumes a valid ArrayBuffer and bypasses an offset check, allowing the crafted length to be accepted. This flaw results in a denial‑of‑service condition; there is no impact on confidentiality or integrity.
Affected Systems
The affected product is the JavaScript library Seroval maintained by lxsmnsyc. Any installation of Seroval prior to version 1.6.3 that processes user‑supplied JSON is vulnerable.
Risk and Exploitability
The flaw has a CVSS score of 7.5, indicating a high severity. EPSS is not available, but the lack of any imposed limit on the array length makes opportunistic exploitation plausible. The vulnerability is not listed in CISA’s KEV catalog, yet it presents a DoS vector that could disrupt any service relying on Seroval. An attacker can exploit the issue remotely by sending a carefully crafted JSON payload that triggers synchronous allocation of a large array, exhausting host resources.
OpenCVE Enrichment