CVE-2023-54404
Received Received - Intake

Zod Schema Validation Memory Exhaustion Vulnerability

Vulnerability report for CVE-2023-54404, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early termination, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
colinhacks zod to 4.6.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2023-54404 is an uncontrolled resource consumption vulnerability in the Zod library (versions up to 4.6.5). It occurs when validating large arrays without length constraints. The handleArrayResult parse logic in $ZodArray accumulates every validation issue for each failing element without limits or early termination, causing excessive memory allocation and potential crashes due to out-of-memory conditions.

Detection Guidance

To detect this vulnerability, check if your system uses Zod library versions up to 4.6.5. Run commands like 'npm list zod' or 'yarn list zod' to verify the installed version. If the version is 4.6.5 or lower, the system is vulnerable.

Impact Analysis

This vulnerability can lead to denial-of-service (DoS) attacks by crashing applications that use Zod for input validation. Attackers can submit large arrays to exhaust system memory, blocking the main thread and disrupting service availability. Applications relying on Zod for security-critical tasks like form validation or HTTP request parsing are particularly at risk.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service (DoS) attacks that exhaust system resources, potentially disrupting services handling sensitive data. GDPR requires data protection measures that ensure availability and integrity of processing systems, while HIPAA mandates safeguards against disruptions that could compromise protected health information. The uncontrolled resource consumption may violate these requirements by making systems unavailable or causing crashes during validation of large inputs.

Mitigation Strategies

Immediately update the Zod library to a version higher than 4.6.5. Use commands like 'npm update zod' or 'yarn upgrade zod' to apply the latest patch. If updating is not possible, implement input validation limits on array sizes to prevent excessive memory consumption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54404. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart