OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-104845: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization

GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100

# Summary deserializeTypedArray casts the source node to ArrayBuffer without checking it and never bounds the element count. Pass a plain object with a length property and it hits the array-like TypedArray constructor, allocating that many elements. The offset guard above it can't stop this: source.byteLength is undefined, so the comparison is always false. The length is one integer in the JSON, so a tiny payload can name any allocation size, and it runs synchronously inside fromJSON, starving the event loop instead of just slowing one request. fromCrossJSON is the same. Impact is unauthenticated CPU/memory exhaustion for any service deserializing untrusted Seroval JSON: same profile as the array-length and nested-depth DoS issues already fixed here. No confidentiality or integrity impact. DataView has the same unchecked cast but throws instead of allocating. A runtime instanceof ArrayBuffer check plus a size cap should fix it.

Upgrade affected packages to a patched version: seroval 1.6.3.

Vendor
Not specified
Product
seroval
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source