Seroval Denial-of-Service Vulnerability via Array Serialization
Vulnerability
A denial-of-service vulnerability has been identified in the Seroval library, specifically in versions through 1.4.0. The issue arises from the deserialization process, which can be manipulated by overriding encoded array lengths with excessively large values. This exploitation leads to a significant increase in processing time, causing potential performance degradation.
Impact
Exploitation of this vulnerability causes a high impact denial-of-service condition, where the application's performance is severely degraded due to increased processing times.
Remediation
Users can upgrade to Seroval version 1.4.1 or later, where this vulnerability has been addressed. Instructions for updating can be found on the Seroval GitHub repository.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
