Description
Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early termination, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.
Published: 2026-10-01
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Zod 4.6.5 allows an attacker to exhaust memory by submitting a very large array to any input that is validated by an array schema without a length constraint. The library accumulates a validation issue object for each element that fails the schema, without any cap or early termination. When the array is large, the process allocates many issue objects, leading to an out‑of‑memory condition and a crash. This results in a denial of service that affects the availability of the entire application.

Affected Systems

Affected JavaScript/TypeScript projects that use the Zod schema‑validation library version 4.6.5 or earlier, provided by the colinhacks organization. The issue is tied to all array schemas lacking a explicit size limit that rely on the default handleArrayResult logic.

Risk and Exploitability

The CVSS base score of 8.2 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of an early‑termination cap makes exploitation straightforward for any endpoint that accepts large array inputs. Attackers can achieve memory exhaustion and crash the process without special privileges; the entry point is likely an unauthenticated or authenticated API that performs array validation with Zod.

Generated by OpenCVE AI on October 1, 2026 at 18:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zod to the latest secure release (v4.6.6 or later) to remove the buffer‑overflow bug.
  • Introduce explicit maximum length constraints on all Zod array schemas to bound the number of elements processed.
  • Configure application and infrastructure limits (e.g., memory quotas, request size limits) to mitigate the impact of unbounded array allocation.

Generated by OpenCVE AI on October 1, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Zod
Zod zod
CPEs cpe:2.3:a:zod:zod:*:*:*:*:*:*:*:*
Vendors & Products Zod
Zod zod

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Colinhacks
Colinhacks zod
Vendors & Products Colinhacks
Colinhacks zod

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early termination, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.
Title Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T21:44:56.091Z

Reserved: 2026-10-01T17:10:41.641Z

Link: CVE-2023-54404

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T18:17:11.040

Modified: 2026-10-01T18:17:11.040

Link: CVE-2023-54404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:33:27Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling