Skip to content
Threat Feed
low advisory

Uncontrolled Resource Consumption in Zod Schema Validation Library

The Zod schema-validation library is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to trigger out-of-memory crashes by submitting large, specially crafted arrays to applications using unconstrained array schemas.

CVE search metadata

CVE search record: CVE-2023-54404. Severity: high. CVSS: 7.5. KEV: no. Product: Zod (<= 4.6.5). Brief: Uncontrolled Resource Consumption in Zod Schema Validation Library. Brief link: https://feed.craftedsignal.io/briefs/2026-10-zod-dos/

The Zod schema-validation library, through version 4.6.5, is susceptible to an uncontrolled resource consumption vulnerability (CVE-2023-54404). The vulnerability originates in the handleArrayResult parsing logic within the $ZodArray component. When an application utilizes a Zod array schema that lacks specific length constraints, an attacker can submit a significantly large array as input. The parser proceeds to accumulate validation issues for every failing element within the array without implementing a cap or early termination mechanism.

This behavior forces the Node.js process to allocate an excessive number of issue objects in memory. For sufficiently large payloads, this allocation spike leads to an out-of-memory (OOM) condition, resulting in an application crash. This vulnerability poses a high risk to service availability, particularly for public-facing APIs that rely on Zod for user-supplied data validation. Developers should ensure all array schemas incorporate strict length constraints and upgrade Zod to the latest available version.

Impact

Successful exploitation results in a denial-of-service condition for applications consuming the vulnerable Zod library. By repeatedly sending crafted arrays, an attacker can maintain the application in an unavailable state, disrupting business operations. The scope of impact includes any web service, API, or background processing unit that utilizes Zod for untrusted input validation.

Recommendation

Prioritized actions for development and security engineering teams:

  • Identify all instances of the Zod library within the application codebase and verify versions in use.
  • Update all dependencies to a version of Zod later than 4.6.5 to remediate CVE-2023-54404.
  • Audit all Zod array schema definitions to ensure .min(), .max(), or .length() constraints are applied to prevent processing of excessively large arrays.
  • Implement request body size limits at the load balancer or web server ingress point to provide defense-in-depth against large payload submissions.

Mitigations

Upgrade Zod to a version beyond 4.6.5

immediate Development

CVE-2023-54404