CVE-2026-23957
Description
A flaw was found in seroval. A remote attacker can exploit this vulnerability by providing specially crafted input that overrides encoded array lengths with an excessively large value during the deserialization process. This manipulation causes the application to significantly increase processing time, leading to a Denial of Service (DoS).
Statement
This vulnerability is rated Important for Red Hat because seroval, a JavaScript value stringification library, can be exploited to cause a Denial of Service. An attacker can provide an excessively large value for encoded array lengths during deserialization, leading to a significant increase in processing time. This affects versions 1.4.0 and below of seroval, which is used in components like forgejo in Fedora and EPEL.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.