{"id":"CVE-2023-54404","summary":"Zod 4.6.5 Uncontrolled Resource Consumption via Array Validation","details":"Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application using an array schema without a length constraint. Attackers can exploit the handleArrayResult parse logic in $ZodArray, which accumulates every validation issue for each failing element with no cap or early termination, causing the process to allocate excessive issue objects and crash due to out-of-memory conditions.","modified":"2026-10-02T11:30:36.510072156Z","published":"2026-10-01T17:11:13.762Z","database_specific":{"cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54404.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54404.json"},{"type":"PACKAGE","url":"https://github.com/colinhacks/zod"},{"type":"ARTICLE","url":"https://github.com/colinhacks/zod/issues/1872"},{"type":"REPORT","url":"https://github.com/colinhacks/zod/pull/6475"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-54404"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/zod-uncontrolled-resource-consumption-via-array-validation"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/colinhacks/zod","events":[{"introduced":"0"},{"last_affected":"59bbc03e10c636b9eb3c393dfeb552819774ec21"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.6.5"}],"source":"AFFECTED_FIELD"}}],"versions":["v4.6.5","v4.6.4","v4.6.3","v4.6.2","v4.6.1","v4.6.0","v4.5.4","v4.5.3","v4.5.2","v4.5.1","v4.5.0","v4.4.3","v4.4.2","v4.4.1","v4.4.0","v4.3.6","v4.3.5","v4.3.4","v4.3.3","v4.3.2","v4.3.1","v4.3.0","v4.2.1","v4.2.0","v4.1.13","v4.1.12","v4.1.11","v4.1.10","v4.1.9","v4.1.8","v4.1.7","v4.1.5","v4.1.4","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.17","v4.0.16","v4.0.15","v4.0.14","v4.0.13","v4.0.12","v4.0.11","v4.0.10","v4.0.9","v4.0.8","v4.0.7","v4.0.6","v3.25.71","v4.0.5","v4.0.4","v3.25","v4.0.3","v4.0.1","v3.25.76","v3.25.75","v3.25.74","v3.25.73","v3.25.72","v3.25.70","v3.25.69","v3.25.68","v3.25.67","v3.25.66","v3.25.65","v3.25.64","v3.25.63","v3.25.62","v3.25.61","v3.25.60","v3.25.59","v3.25.58","v3.25.57","v3.25.56","v3.25.55","v3.25.54","v3.25.53","v3.25.52","v3.25.51","v3.25.50","v3.25.49","v3.25.48","v3.25.47","v3.25.46","v3.25.45","v3.25.44","v3.25.43","v3.25.42","v3.25.41","v3.25.40","v3.25.39","v3.25.38","v3.25.37","v3.25.36","v3.25.35","v3.25.34","v3.25.33","v3.25.32","v3.25.31","v3.25.30","v3.25.29","v3.25.28","v3.25.27","v3.25.26","v3.25.25","v3.25.24","v3.25.23","v3.25.22","v3.25.21","v3.25.20","v3.25.18","v3.25.17","v3.25.16","v3.25.15","v3.25.14","v3.25.13","v3.25.12","v3.25.11","v3.25.10","v3.25.9","v3.24.4","v3.24.3","v3.24.2","v3.24.1","v3.24.0","v3.23.8","v3.23.7","v3.23.6","v3.23.5","v3.23.4","v3.23.3","v3.23.2","v3.23.1","v3.23.0","v3.23.0-beta.0","v3.22.4","v3.22.3","v3.22.2","v3.22.1","v3.22.0","v3.21.4","v3.21.3","v3.21.2","v3.21.1","v3.21.0","v3.20.6","v3.20.5","v3.20.4","v3.20.3","v3.20.2","v3.20.1","v3.20","v3.20.0","v3.19.1","v3.19.0","v3.18.0","v3.17.10","v3.17.9","v3.17.8","v3.17.7","v3.17.6","v3.17.5","v3.17.4","v3.17.3","v3.17.2","v3.17.0","v3.16.1","v3.16.0","v3.15.1","v3.15.0","v3.14.5","v3.14.4","v3.14.3","v3.14.2","v3.14.1","v3.14.0","v3.13.4","v3.13.2","v3.12.0","v3.11.6","v3.11.4","v3.11.3","v3.10.3","v3.9.0","v3.8.0","v3.7.3","v3.5.0","v3.4.2","v3.4.0","v3.2","v3.1.0","v3.0.0","v3.0.0-alpha.18","1.10.2","v1.9","v1.8","1.7","v1.0","v1.2.0","v1.1.2","1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-54404.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}