and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3j22-8qj3-26mx | Seroval affected by Denial of Service via Deeply Nested Objects |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lxsmnsyc
Lxsmnsyc seroval |
|
| Vendors & Products |
Lxsmnsyc
Lxsmnsyc seroval |
Thu, 22 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 22 Jan 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached. | |
| Title | Seroval affected by Denial of Service via Deeply Nested Objects | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-22T12:50:51.270Z
Reserved: 2026-01-19T18:49:20.659Z
Link: CVE-2026-24006
Updated: 2026-01-22T12:50:46.861Z
Status : Received
Published: 2026-01-22T03:15:47.933
Modified: 2026-01-22T03:15:47.933
Link: CVE-2026-24006
OpenCVE Enrichment
Updated: 2026-01-22T10:08:01Z
Github GHSA