Description
Overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service).
Recommendation
Update the seroval package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.2.0, <= 1.4.0
- Patched version(s): 1.4.1
References
Could your website be exposed too?
SmartScanner can check your website for seroval affected by Denial of Service via RegExp serialization and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Seroval affected by Denial of Service via Array serialization - CVE-2026-23957
- Seroval affected by Denial of Service via Deeply Nested Objects - CVE-2026-24006
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867
- path-to-regexp vulnerable to Denial of Service via sequential optional groups - CVE-2026-4926


