Resource exhaustion in Serialize-javascript - CVE-2026-34043
Published: April 28, 2026
Serialize-javascript
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the serialize() function when serializing a specially crafted array-like object. A remote attacker can supply a crafted array-like object to cause a denial of service.
Exploitation can cause 100% CPU usage and the process may hang indefinitely.