An open index of dependabot pull requests across open source projects.

seroval

Ecosystem:
npm
Package URL:
pkg:npm/seroval
Total PRs:
143 Dependabot PRs
Latest PR:
about 1 month ago
Unique Repositories:
114 repositories
Unique Repos (30 days):
2 repositories
Security Advisories
Seroval affected by Denial of Service via Deeply Nested Objects
GHSA-3j22-8qj3-26mx CVE-2026-24006 HIGH published 5 months ago • updated 24 days ago
Serialization of objects with extreme depth can **exceed the maximum call stack limit**. **Mitigation**: `Seroval` introduces a `depthLimit` p...
Seroval affected by Denial of Service via Array serialization
GHSA-66fc-rw6m-c2q6 CVE-2026-23957 HIGH published 5 months ago • updated 24 days ago
Overriding encoded array lengths by replacing them with an excessively large value causes the deserialization process to **significantly increase p...
seroval affected by Denial of Service via RegExp serialization
GHSA-hx9m-jf43-8ffr CVE-2026-23956 HIGH published 5 months ago • updated 24 days ago
Overriding RegExp serialization with extremely large patterns can **exhaust JavaScript runtime memory** during deserialization. Additionally, overr...
seroval Affected by Prototype Pollution via JSON Deserialization
GHSA-hj76-42vx-jwp4 CVE-2026-23736 HIGH published 5 months ago • updated 7 days ago
Due to improper input validation, a malicious object key can lead to prototype pollution during JSON deserialization. This affects only JSON deseri...
seroval Affected by Remote Code Execution via JSON Deserialization
GHSA-3rxj-6cgf-8cfw CVE-2026-23737 HIGH published 5 months ago • updated 26 days ago
Improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code execution. The vulnerability can be exploited ...
Recent PRs (filtered by: Patch PRs )
Bump seroval from 1.4.0 to 1.4.2

mitre/tir #161

1.4.0 → 1.4.2 Patch PR
Open 5 months ago 1 comment
mitre
Bump the npm group with 11 updates

poad/tauri-example #2121

1.3.1 → 1.3.2 Patch PR
Closed about 1 year ago 2 comments
poad
Package Details
Name: seroval
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/seroval
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 5
View All npm Advisories
Package Information
Description:

Stringify JS values

Repository: https://github.com/lxsmnsyc/seroval
Homepage: https://github.com/lxsmnsyc/seroval/tree/main/packages/seroval
Latest Release: 1.3.2
about 1 year ago
Dependent Repos: 1,628
Dependent Packages: 8
Downloads: 1,997,309
Ranking: Top 0.5288% by dependent repos Top 0.3849% by downloads Top 4.3828% by dependent pkgs
PR Status
Open 69 (48.3%)
Merged 5 (3.5%)
Closed 65 (45.5%)
PR Types
Major 2 (1.4%)
Minor 82 (57.3%)
Patch 55 (38.5%)