<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:seroval:seroval:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aserovalserovalnode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:45:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aserovalserovalnode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service via Unchecked TypedArray Length in Seroval</title><link>https://feed.craftedsignal.io/briefs/2026-10-seroval-dos/</link><pubDate>Tue, 06 Oct 2026 00:45:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-seroval-dos/</guid><description>The Seroval library is vulnerable to unauthenticated memory and CPU exhaustion due to an unchecked TypedArray length property during JSON deserialization, leading to event loop starvation.</description><content:encoded><![CDATA[<p>The Seroval library (versions 1.6.2 and earlier) contains a critical vulnerability in the <code>deserializeTypedArray</code> and <code>fromCrossJSON</code> functions, identified as CVE-2026-104845. The library fails to validate the source node when casting to an <code>ArrayBuffer</code>, specifically failing to bound the element count during deserialization. By supplying a specially crafted JSON payload containing a large integer in the <code>length</code> property, an attacker can trigger massive synchronous memory allocations. Because this process occurs within the event loop, it causes immediate service-wide resource exhaustion and denial of service. Unlike the <code>DataView</code> implementation which properly throws an error, the <code>TypedArray</code> handling remains susceptible to this primitive. This vulnerability impacts any service utilizing Seroval to process untrusted JSON inputs.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in unauthenticated denial of service by starving the application event loop. This leads to high CPU utilization and potential process crashes due to memory exhaustion. The impact is limited to availability; there is no identified risk to confidentiality or integrity. Any application environment utilizing Seroval to deserialize external input is at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Seroval package to a patched version (beyond 1.6.2) immediately upon release by the maintainers.</li>
<li>Implement request size limiting at the API gateway or proxy level to prevent the ingestion of excessively large or malicious JSON payloads before they reach the deserialization layer.</li>
<li>Validate incoming JSON structure schema-side before passing payloads to the Seroval <code>fromJSON</code> or <code>fromCrossJSON</code> methods.</li>
<li>Monitor server resource metrics (CPU and Heap memory) for sudden, synchronous spikes that correlate with incoming POST requests to identify potential exploitation attempts.</li>
</ol>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>deserialization</category></item></channel></rss>