Seroval affected by Denial of Service via Deeply Nested Objects
Description
Published by the National Vulnerability Database
Jan 22, 2026
Published to the GitHub Advisory Database
Jan 22, 2026
Reviewed
Jan 22, 2026
Last updated
Jan 22, 2026
Serialization of objects with extreme depth can exceed the maximum call stack limit.
Mitigation:
Serovalintroduces adepthLimitparameter in serialization/deserialization methods. An error will be thrown if the depth limit is reached.References