CVE-2026-24006
Description
A flaw was found in seroval. An attacker could exploit this vulnerability by providing a specially crafted JavaScript (JS) object with extreme depth during the serialization process. This could lead to exceeding the maximum call stack limit, resulting in a Denial of Service (DoS) for the application using the seroval library.
Statement
This vulnerability is rated Important for Red Hat products as it can lead to a Denial of Service in applications utilizing the Seroval library. Specifically, deeply nested objects processed by Seroval versions 1.4.0 and below can exhaust the call stack, causing application instability. Red Hat products like Forgejo in Fedora and EPEL are affected if they use vulnerable versions of Seroval.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.