← back
CVE-2026-24006

Seroval affected by Denial of Service via Deeply Nested Objects

CVSS 7.5 HIGHEPSS 0.4%CWE-770
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
lxsmnsyc · seroval

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →