CVE-2026-23956

seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during deserialization. Additionally, overriding RegExp serialization with patterns that trigger catastrophic backtracking can lead to ReDoS (Regular Expression Denial of Service). This issue has been fixed in version 1.4.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-22 02:15

Updated : 2026-01-26 15:04


NVD link : CVE-2026-23956

Mitre link : CVE-2026-23956

CVE.ORG link : CVE-2026-23956


JSON object : View

Products Affected

No product.

CWE
CWE-1333

Inefficient Regular Expression Complexity