CVE-2026-104845
Deferred Deferred - Pending Action

Seroval Deserialization Leading to CPU or Memory Exhaustion

Vulnerability report for CVE-2026-104845, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray constructor to synchronously allocate the selected number of elements and exhaust CPU or memory while starving the event loop. The offset check does not reject the crafted source because source.byteLength is undefined. DataView reaches a similar unchecked cast but throws rather than allocating, and the issue has no identified confidentiality or integrity impact. This issue is fixed in version 1.6.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
seroval seroval 1.6.3
lxsmnsyc seroval to 1.6.2 (inc)
lxsmnsyc seroval-plugins 1.6.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a memory exhaustion issue in the seroval library. It occurs during JSON deserialization when the deserializeTypedArray function casts an untrusted source value to an ArrayBuffer without validating it. An attacker can send a small JSON object with a large length value, causing the TypedArray constructor to allocate excessive memory synchronously. This leads to CPU or memory exhaustion and event loop starvation.

Detection Guidance

To detect this vulnerability, monitor for unusual memory or CPU usage spikes during JSON deserialization processes using seroval versions prior to 1.6.3. Check for processes handling large TypedArray allocations or event loop starvation. Use system monitoring tools like top, htop, or ps to observe resource consumption.

Impact Analysis

This vulnerability can cause denial of service by exhausting system resources. It may lead to application crashes, degraded performance, or complete unavailability of services relying on the seroval library. The impact is limited to availability as there is no identified confidentiality or integrity risk.

Mitigation Strategies

Immediately upgrade seroval to version 1.6.3 or later to apply the fix that enforces a maximum length limit of 1,000,000 elements for TypedArrays and DataView objects. Review and update any dependencies in your project to ensure they use the patched version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104845. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart