Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
🔗 CVE IDs covered (1)
📋 Description
Summary
deserializeTypedArray casts the source node to ArrayBuffer without checking it and never bounds the element count. Pass a plain object with a length property and it hits the array-like TypedArray constructor, allocating that many elements. The offset guard above it can't stop this: source.byteLength is undefined, so the comparison is always false.
The length is one integer in the JSON, so a tiny payload can name any allocation size, and it runs synchronously inside fromJSON, starving the event loop instead of just slowing one request. fromCrossJSON is the same.
Impact is unauthenticated CPU/memory exhaustion for any service deserializing untrusted Seroval JSON: same profile as the array-length and nested-depth DoS issues already fixed here. No confidentiality or integrity impact. DataView has the same unchecked cast but throws instead of allocating. A runtime instanceof ArrayBuffer check plus a size cap should fix it.
🎯 Affected products1
- npm/seroval:<= 1.6.2
🔗 References (5)
- https://github.com/lxsmnsyc/seroval/security/advisories/GHSA-jp82-f5mq-hwhp
- https://nvd.nist.gov/vuln/detail/CVE-2026-104845
- https://github.com/lxsmnsyc/seroval/commit/ac0163e420ac7dcbbefac4d069bcefad300a4851
- https://github.com/lxsmnsyc/seroval/commit/e54a6f62784b9e48e3a5fa2ab4089ca69fb8996e
- https://github.com/advisories/GHSA-jp82-f5mq-hwhp