Debian Node-Serialize-Javascript vulnerabilities
2 known vulnerabilities affecting debian/node-serialize-javascript.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-34043MEDIUMCVSS 5.9fixed in node-serialize-javascript 7.0.5+~5.0.4-1 (forky)2026
CVE-2026-34043 [MEDIUM] CVE-2026-34043: node-serialize-javascript - Serialize JavaScript to a superset of JSON that includes regular expressions and...
Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, there is a Denial of Service (DoS) vulnerability caused by CPU exhaustion. When serializing a specially crafted "array-like" object (an object that inherits from Array.prototype but has a very large length property), the process ent
debian
CVE-2024-11831MEDIUMCVSS 5.4fixed in node-serialize-javascript 6.0.0-2+deb12u1 (bookworm)2024
CVE-2024-11831 [MEDIUM] CVE-2024-11831: node-serialize-javascript - A flaw was found in npm-serialize-javascript. The vulnerability occurs because t...
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS)
debian