Sceawere
Vulnerability Detail
CVE-2023-54404UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zod Uncontrolled Resource Consumption Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- colinhacks
- Product
- zod
- Attack Type
- Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early termination, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-01T18:17:11.040Z",
"pubdate": "2026-10-01T18:17:11.040Z",
"executiveSummary": "The Zod schema-validation library, through version 4.6.5, is susceptible to an uncontrolled resource consumption vulnerability stemming from improper input validation handling within array schemas.\nThe vulnerability type is categorized as an uncontrolled resource consumption flaw, specifically leading to memory exhaustion (Out-of-Memory).\nAffected systems include any application utilizing Zod for input validation where array schemas are implemented without explicit length constraints.\nAn attacker can exploit this by submitting a maliciously crafted, oversized array payload to an endpoint. The lack of early termination in the validation logic forces the process to allocate excessive memory to track validation issues, eventually leading to process termination or service denial.\nThis vulnerability does not require authentication or elevated privileges, as it is triggered during the standard schema parsing phase of input handling, making it a viable vector for remote denial-of-service (DoS) attacks.\nRisk implications are high for applications that process user-supplied JSON data, as the resource exhaustion occurs synchronously during parsing, effectively blocking the event loop or crashing the Node.js process.",
"technicalDetails": "The root cause of this vulnerability lies in the 'handleArrayResult' logic within the '$ZodArray' implementation. When Zod processes an array schema, it attempts to validate each element individually. If an array contains a large number of invalid elements, the library creates an issue object for every single failure detected.\nIn versions 4.6.5 and earlier, the parsing logic lacks a configurable cap or a mechanism for early termination upon reaching a threshold of errors. Consequently, the memory allocation scales linearly with the number of invalid elements provided in the input array.\nThe attack flow commences when an attacker submits an HTTP request containing an array significantly larger than expected by the application logic. The '$ZodArray' parser iterates through each element of the input array. For every element that fails validation against the defined schema, the 'handleArrayResult' function instantiates and accumulates a complex error object.\nAs these issue objects populate the memory heap, the application experiences a rapid spike in memory usage. Because there is no 'fail-fast' logic implemented, the validation process continues until the entire input array has been processed, even if the error count has already reached a level indicative of a malicious or malformed request.\nThe memory consumption becomes excessive, eventually exceeding the V8 heap limit allocated to the Node.js process. This triggers an 'Out of Memory' (OOM) error, resulting in a process crash and a denial-of-service state. Because the validation occurs synchronously during the standard parse cycle, this impact is immediate and can consume CPU resources while triggering garbage collection attempts, further degrading performance before the crash occurs.\nExploitation is straightforward as it does not require bypasses for authentication or complex cryptographic maneuvering. An attacker only needs a network path to an endpoint that utilizes an unconstrained Zod array schema. The payload requires no special permissions, only the ability to send a sufficiently large array that forces the accumulation of thousands or millions of error objects, depending on the available heap size of the target environment."
}