Impact
The vulnerability in Zod 4.6.5 allows an attacker to exhaust memory by submitting a very large array to any input that is validated by an array schema without a length constraint. The library accumulates a validation issue object for each element that fails the schema, without any cap or early termination. When the array is large, the process allocates many issue objects, leading to an out‑of‑memory condition and a crash. This results in a denial of service that affects the availability of the entire application.
Affected Systems
Affected JavaScript/TypeScript projects that use the Zod schema‑validation library version 4.6.5 or earlier, provided by the colinhacks organization. The issue is tied to all array schemas lacking a explicit size limit that rely on the default handleArrayResult logic.
Risk and Exploitability
The CVSS base score of 8.2 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of an early‑termination cap makes exploitation straightforward for any endpoint that accepts large array inputs. Attackers can achieve memory exhaustion and crash the process without special privileges; the entry point is likely an unauthenticated or authenticated API that performs array validation with Zod.
OpenCVE Enrichment