GHSA-p5wg-g6qr-c7cg

Suggest an improvement
Source
https://github.com/advisories/GHSA-p5wg-g6qr-c7cg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-p5wg-g6qr-c7cg/GHSA-p5wg-g6qr-c7cg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p5wg-g6qr-c7cg
Aliases
Downstream
CGA (18)
MINI (5)
Withdrawn
2026-02-03T17:43:56Z
Published
2026-01-26T18:31:29Z
Modified
2026-09-10T03:50:33Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Withdrawn Advisory: eslint has a Stack Overflow when serializing objects with circular references
Details

Withdrawn Advisory

This advisory has been withdrawn because RuleTester is used for testing rules during development and results in a error rather than crashing the application.

Original Description

There is a Stack Overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleTester.run() method, which validates test cases and checks for duplicates. During validation, the internal function checkDuplicateTestCase() is called, which in turn uses the isSerializable() function for serialization checks. When a circular reference object is passed in, isSerializable() enters infinite recursion, ultimately causing a Stack Overflow.

Database specific
{
    "cwe_ids":  [
        "CWE-674"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-29T14:58:17Z",
    "nvd_published_at":  "2026-01-26T16:15:58Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / eslint

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.26.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-p5wg-g6qr-c7cg/GHSA-p5wg-g6qr-c7cg.json"