vulnerabilityCVE-2026-104845
CVE-2026-104845
A flaw was found in seroval. A remote attacker can cause a Denial of Service (DoS) by providing crafted JSON input containing an excessively large array length during data deserialization. Due to missing bounds validation when reconstructing array structures, the application synchronously allocates excessive memory and processor resources, blocking the event loop and making the service unresponsive.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action