Uncontrolled Resource Consumption in Zod Schema-Validation Library
CVE-2023-54404

8.2HIGH

Key Information:

Vendor

Colinhacks

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2023-54404?

The Zod schema-validation library, up to version 4.6.5, exhibits an uncontrolled resource consumption vulnerability. This issue arises when an attacker submits a large array to an application that utilizes an array schema without enforcing length constraints. The flaw in the handleArrayResult parsing logic within $ZodArray results in the accumulation of validation issues for each failing element without any limit or early exit conditions. Consequently, this leads to significant memory allocation, potentially causing the application to exhaust its memory resources and crash.

Affected Version(s)

zod 0 <= 4.6.5

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Axel Habermaier (axel-habermaier)
Alessio Della Libera
.