Vulnerabilities/

Seroval affected by Denial of Service via Deeply Nested Objects

Severity:
High

Description

Serialization of objects with extreme depth can exceed the maximum call stack limit.

Mitigation:
Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

Recommendation

Update the seroval package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
seroval
Anything's wrong? Let us know Last updated on January 22, 2026