An open index of dependabot pull requests across open source projects.

seroval

Ecosystem:
npm
Package URL:
pkg:npm/seroval
Total PRs:
106 Dependabot PRs
Latest PR:
9 days ago
Unique Repositories:
87 repositories
Unique Repos (30 days):
15 repositories
Security Advisories
Seroval affected by Denial of Service via Array serialization
GHSA-66fc-rw6m-c2q6 CVE-2026-23957 HIGH published 2 months ago • updated 24 days ago
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to **significantly increase p...
seroval affected by Denial of Service via RegExp serialization
GHSA-hx9m-jf43-8ffr CVE-2026-23956 HIGH published 2 months ago • updated 24 days ago
Overriding RegExp serialization with extremely large patterns can **exhaust JavaScript runtime memory** during deserialization. Additionally, overr...
seroval Affected by Remote Code Execution via JSON Deserialization
GHSA-3rxj-6cgf-8cfw CVE-2026-23737 HIGH published 2 months ago • updated 24 days ago
Improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. The vulnerability can be exploited ...
seroval Affected by Prototype Pollution via JSON Deserialization
GHSA-hj76-42vx-jwp4 CVE-2026-23736 HIGH published 2 months ago • updated 24 days ago
Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This affects only JSON deseri...
Seroval affected by Denial of Service via Deeply Nested Objects
GHSA-3j22-8qj3-26mx CVE-2026-24006 HIGH published 2 months ago • updated 24 days ago
Serialization of objects with extreme depth can **exceed the maximum call stack limit**. **Mitigation**: `Seroval` introduces a `depthLimit` p...
Recent PRs
Bump seroval and solid-js

poliberry/crystal #19

1.3.2 → 1.5.0 Minor PR
Open about 1 month ago 1 comment
poliberry
Bump seroval from 1.0.4 to 1.5.0

koo19/chatbot-ui #5

1.0.4 → 1.5.0 Minor PR
Open about 1 month ago 1 comment
koo19
Bump seroval and solid-js in /site

zahash/mona #4

1.3.2 → 1.5.0 Minor PR
Closed about 1 month ago 1 comment
zahash
Bump seroval and solid-js

neidigsi/simonneidig_reactjs #335

1.3.2 → 1.5.0 Minor PR
Open about 2 months ago 1 comment
neidigsi
Package Details
Name: seroval
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/seroval
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 5
View All npm Advisories
Package Information
Description:

Stringify JS values

Repository: https://github.com/lxsmnsyc/seroval
Homepage: https://github.com/lxsmnsyc/seroval/tree/main/packages/seroval
Latest Release: 1.3.2
10 months ago
Dependent Repos: 1,628
Dependent Packages: 8
Downloads: 1,997,309
Ranking: Top 0.5288% by dependent repos Top 0.3849% by downloads Top 4.3828% by dependent pkgs
PR Status
Open 51 (48.1%)
Merged 5 (4.7%)
Closed 46 (43.4%)
PR Types
Minor 58 (54.7%)
Patch 44 (41.5%)