ZERO
Back
vulnerabilityCVE-2026-104845

CVE-2026-104845

A flaw was found in seroval. A remote attacker can cause a Denial of Service (DoS) by providing crafted JSON input containing an excessively large array length during data deserialization. Due to missing bounds validation when reconstructing array structures, the application synchronously allocates excessive memory and processor resources, blocking the event loop and making the service unresponsive.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action