{"id":"CVE-2023-54404","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-54404","summary":"Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation","details":"Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early termination, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.","published":"2026-10-01T17:11:13.762Z","modified":"2026-10-02T11:30:36.510072156Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/colinhacks/zod/pull/6475","label":"colinhacks/zod#6475"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54404.json"},{"type":"PACKAGE","url":"https://github.com/colinhacks/zod"},{"type":"ARTICLE","url":"https://github.com/colinhacks/zod/issues/1872"},{"type":"REPORT","url":"https://github.com/colinhacks/zod/pull/6475"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-54404"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/zod-uncontrolled-resource-consumption-via-array-validation"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T11:30:36.510072156Z"}}