Description
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to significantly increase processing time.
Mitigation:Seroval no longer encodes array lengths. Instead, it computes length using Array.prototype.length during deserialization.
Recommendation
Update the seroval package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.4.0
- Patched version(s): 1.4.1
References
Could your website be exposed too?
SmartScanner can check your website for Seroval affected by Denial of Service via Array serialization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- seroval affected by Denial of Service via RegExp serialization - CVE-2026-23956
- Seroval affected by Denial of Service via Deeply Nested Objects - CVE-2026-24006
- Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects - CVE-2026-34043
- jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions - CVE-2026-25535


