Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24006

Опубликовано: 22 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a depthLimit parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lxsmnsyc:seroval:*:*:*:*:*:node.js:*:*
Версия до 1.4.1 (исключая)

EPSS

Процентиль: 33%
0.00403
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
7 месяцев назад

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Seroval introduces a `depthLimit` parameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.

CVSS3: 7.5
github
7 месяцев назад

Seroval affected by Denial of Service via Deeply Nested Objects

EPSS

Процентиль: 33%
0.00403
Низкий

7.5 High

CVSS3

Дефекты

CWE-770