CVE-2026-104845: CWE-770: Allocation of Resources Without Limits or Throttling in lxsmnsyc seroval
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray constructor to synchronously allocate the selected number of elements and exhaust CPU or memory while starving the event loop. The offset check does not reject the crafted source because source.byteLength is undefined. DataView reaches a similar unchecked cast but throws rather than allocating, and the issue has no identified confidentiality or integrity impact. This issue is fixed in version 1.6.3.
AI Analysis
Technical Summary
The seroval library facilitates JavaScript value stringification beyond JSON.stringify capabilities. In versions before 1.6.3, the deserializeTypedArray function in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer without bounding the serialized element count. An attacker can exploit this by supplying a small JSON object with a large length property, causing the TypedArray constructor to allocate a large number of elements synchronously. This results in CPU or memory exhaustion and event loop starvation. The offset check does not reject the crafted source because source.byteLength is undefined. A similar issue exists with DataView, which throws an error instead of allocating. There is no confidentiality or integrity impact. The vulnerability is fixed in seroval version 1.6.3.
Potential Impact
An attacker can cause denial of service by exhausting CPU or memory resources, leading to event loop starvation. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Upgrade seroval to version 1.6.3 or later, where this issue is fixed. No other mitigation is required as the vulnerability is addressed by the official fix.
CVE-2026-104845: CWE-770: Allocation of Resources Without Limits or Throttling in lxsmnsyc seroval
Description
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray constructor to synchronously allocate the selected number of elements and exhaust CPU or memory while starving the event loop. The offset check does not reject the crafted source because source.byteLength is undefined. DataView reaches a similar unchecked cast but throws rather than allocating, and the issue has no identified confidentiality or integrity impact. This issue is fixed in version 1.6.3.
CVSS v3.1
Score 7.5high
Affected software
lxsmnsyc
seroval
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The seroval library facilitates JavaScript value stringification beyond JSON.stringify capabilities. In versions before 1.6.3, the deserializeTypedArray function in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer without bounding the serialized element count. An attacker can exploit this by supplying a small JSON object with a large length property, causing the TypedArray constructor to allocate a large number of elements synchronously. This results in CPU or memory exhaustion and event loop starvation. The offset check does not reject the crafted source because source.byteLength is undefined. A similar issue exists with DataView, which throws an error instead of allocating. There is no confidentiality or integrity impact. The vulnerability is fixed in seroval version 1.6.3.
Potential Impact
An attacker can cause denial of service by exhausting CPU or memory resources, leading to event loop starvation. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Upgrade seroval to version 1.6.3 or later, where this issue is fixed. No other mitigation is required as the vulnerability is addressed by the official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-02T14:38:43.243Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abfd567a43b0b3b89d3b444
Added to database: 10/02/2026, 16:01:43 UTC
Last enriched: 10/02/2026, 16:16:00 UTC
Last updated: 10/03/2026, 03:09:26 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.