{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aserovalserovalnode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:seroval:seroval:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-104845"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["seroval (\u003c= 1.6.2)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","deserialization"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Seroval library (versions 1.6.2 and earlier) contains a critical vulnerability in the \u003ccode\u003edeserializeTypedArray\u003c/code\u003e and \u003ccode\u003efromCrossJSON\u003c/code\u003e functions, identified as CVE-2026-104845. The library fails to validate the source node when casting to an \u003ccode\u003eArrayBuffer\u003c/code\u003e, specifically failing to bound the element count during deserialization. By supplying a specially crafted JSON payload containing a large integer in the \u003ccode\u003elength\u003c/code\u003e property, an attacker can trigger massive synchronous memory allocations. Because this process occurs within the event loop, it causes immediate service-wide resource exhaustion and denial of service. Unlike the \u003ccode\u003eDataView\u003c/code\u003e implementation which properly throws an error, the \u003ccode\u003eTypedArray\u003c/code\u003e handling remains susceptible to this primitive. This vulnerability impacts any service utilizing Seroval to process untrusted JSON inputs.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthenticated denial of service by starving the application event loop. This leads to high CPU utilization and potential process crashes due to memory exhaustion. The impact is limited to availability; there is no identified risk to confidentiality or integrity. Any application environment utilizing Seroval to deserialize external input is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Seroval package to a patched version (beyond 1.6.2) immediately upon release by the maintainers.\u003c/li\u003e\n\u003cli\u003eImplement request size limiting at the API gateway or proxy level to prevent the ingestion of excessively large or malicious JSON payloads before they reach the deserialization layer.\u003c/li\u003e\n\u003cli\u003eValidate incoming JSON structure schema-side before passing payloads to the Seroval \u003ccode\u003efromJSON\u003c/code\u003e or \u003ccode\u003efromCrossJSON\u003c/code\u003e methods.\u003c/li\u003e\n\u003cli\u003eMonitor server resource metrics (CPU and Heap memory) for sudden, synchronous spikes that correlate with incoming POST requests to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T00:45:14Z","date_published":"2026-10-06T00:45:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-seroval-dos/","summary":"The Seroval library is vulnerable to unauthenticated memory and CPU exhaustion due to an unchecked TypedArray length property during JSON deserialization, leading to event loop starvation.","title":"Denial of Service via Unchecked TypedArray Length in Seroval","url":"https://feed.craftedsignal.io/briefs/2026-10-seroval-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:seroval:seroval:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}