216.73.217.22

CVE-2026-23956

· Published 22/01/2026 02:15 · Modified 22/01/2026 02:15

Labels: CVE-2026-23956 2026-01-22CVE-2026-23956CWE-1333[email protected]

Essential information

Published
22/01/2026 02:15
Modified
22/01/2026 02:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service). This issue has been fixed in version 1.4.1.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
seroval / seroval cpe:2.3:a:seroval:seroval:<1.4.1:*:*:*:*:*:*:*

References