Vulnerabilities/

seroval affected by Denial of Service via RegExp serialization

Severity:
High

Description

Overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service).

Recommendation

Update the seroval package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
seroval
Anything's wrong? Let us know Last updated on January 22, 2026