Resource exhaustion in Serialize-javascript - CVE-2026-34043
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the serialize() function when serializing a specially crafted array-like object. A remote attacker can supply a crafted array-like object to cause a denial of service.
Exploitation can cause 100% CPU usage and the process may hang indefinitely.
Affected software
Event Processing
IBM Event Endpoint Management
Data Cataloging
QRadar Threat Intelligence
IBM Fusion HCI
Confluence Data Center
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dotnet8.0 (Red Hat package)
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-34043
Event Processing - update to 1.5.5
IBM Fusion HCI - update to 2.13.0
Confluence Data Center - addressed in versions 9.2.21, 10.2.14
IBM Event Endpoint Management - update to 11.9.0
Data Cataloging - update to 2.5.3
QRadar Threat Intelligence - update to 2.6.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.65, 4.17.55
dotnet8.0 (Red Hat package) - addressed in versions 8.0.127-1.el8_10, 8.0.127-1.el9_4, 8.0.127-1.el9_8, 8.0.127-1.el10_0, 8.0.127-1.el10_2
External References
Related Security Bulletins
- Resource exhaustion in Serialize-javascript
- Red Hat Enterprise Linux 10 update for .NET 8.0
- Red Hat Enterprise Linux 8 update for .NET 8.0
- Red Hat Enterprise Linux 9 update for .NET 8.0
- Red Hat Enterprise Linux 10 update for .NET 8.0
- Red Hat Enterprise Linux 9 update for .NET 8.0
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- IBM Fusion, IBM Fusion HCI and IBM Fusion Data Cataloging update for serialize-javascript
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Event Processing
- Multiple vulnerabilities in IBM QRadar Threat Intelligence
- IBM Event Endpoint Management update for JavaScript