Uncontrolled Resource Consumption in Zod Schema-Validation Library
CVE-2023-54404
8.2HIGH
What is CVE-2023-54404?
The Zod schema-validation library, up to version 4.6.5, exhibits an uncontrolled resource consumption vulnerability. This issue arises when an attacker submits a large array to an application that utilizes an array schema without enforcing length constraints. The flaw in the handleArrayResult parsing logic within $ZodArray results in the accumulation of validation issues for each failing element without any limit or early exit conditions. Consequently, this leads to significant memory allocation, potentially causing the application to exhaust its memory resources and crash.
Affected Version(s)
zod 0 <= 4.6.5
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Axel Habermaier (axel-habermaier)
Alessio Della Libera
