<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:zod:zod:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3azodzod/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:23:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3azodzod/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Uncontrolled Resource Consumption in Zod Schema Validation Library</title><link>https://feed.craftedsignal.io/briefs/2026-10-zod-dos/</link><pubDate>Thu, 01 Oct 2026 20:23:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-zod-dos/</guid><description>The Zod schema-validation library is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to trigger out-of-memory crashes by submitting large, specially crafted arrays to applications using unconstrained array schemas.</description><content:encoded><![CDATA[<p>The Zod schema-validation library, through version 4.6.5, is susceptible to an uncontrolled resource consumption vulnerability (CVE-2023-54404). The vulnerability originates in the handleArrayResult parsing logic within the $ZodArray component. When an application utilizes a Zod array schema that lacks specific length constraints, an attacker can submit a significantly large array as input. The parser proceeds to accumulate validation issues for every failing element within the array without implementing a cap or early termination mechanism.</p>
<p>This behavior forces the Node.js process to allocate an excessive number of issue objects in memory. For sufficiently large payloads, this allocation spike leads to an out-of-memory (OOM) condition, resulting in an application crash. This vulnerability poses a high risk to service availability, particularly for public-facing APIs that rely on Zod for user-supplied data validation. Developers should ensure all array schemas incorporate strict length constraints and upgrade Zod to the latest available version.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a denial-of-service condition for applications consuming the vulnerable Zod library. By repeatedly sending crafted arrays, an attacker can maintain the application in an unavailable state, disrupting business operations. The scope of impact includes any web service, API, or background processing unit that utilizes Zod for untrusted input validation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security engineering teams:</p>
<ul>
<li>Identify all instances of the Zod library within the application codebase and verify versions in use.</li>
<li>Update all dependencies to a version of Zod later than 4.6.5 to remediate CVE-2023-54404.</li>
<li>Audit all Zod array schema definitions to ensure .min(), .max(), or .length() constraints are applied to prevent processing of excessively large arrays.</li>
<li>Implement request body size limits at the load balancer or web server ingress point to provide defense-in-depth against large payload submissions.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>supply-chain</category></item></channel></rss>