CVE-2023-54404: 
Grafana Análise e mitigação de vulnerabilidades

Visão geral

CVE-2023-54404 is an uncontrolled resource consumption (Denial of Service) vulnerability in the Zod schema-validation library affecting all versions through 4.6.5. An unauthenticated remote attacker can exhaust the memory of an application by submitting a large array to any endpoint that validates input using a Zod array schema without a length constraint. The vulnerability was originally reported as a GitHub issue in January 2023 and formally disclosed in October 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (Github Advisory, Red Hat Bugzilla).

Detalhes técnicos

The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in the handleArrayResult parse logic of the $ZodArray class. When Zod validates an array, it accumulates one validation issue object per failing element with no cap, early-exit mechanism, or maximum issue count. Submitting a very large array (e.g., new Array(10_000_000).fill(invalidValue)) causes the Node.js process to allocate millions of issue objects, exhausting available heap memory and crashing the process. The issue was first raised publicly in GitHub Issue #1872, and the fix was implemented via PR #6475, which introduced an abortEarly parse option that stops validation at the first aborting error in each container loop (Github Advisory, Zod Issue, Zod PR).

Impacto

Successful exploitation results in a complete availability impact — the targeted application process crashes due to out-of-memory conditions, causing a denial of service. There is no confidentiality or integrity impact; the vulnerability cannot be used to read or modify data. Any application that exposes a network-accessible endpoint performing Zod array validation without explicit length constraints is at risk, and a single malicious request can bring down the service (Github Advisory, Red Hat Bugzilla).

Exploração

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, reflecting a currently low probability of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the lack of a formal PoC, the attack technique is straightforward and requires no authentication, privileges, or user interaction — any attacker who can send an HTTP request to a vulnerable endpoint can trigger the condition (Github Advisory).

Etapas de exploração

  1. Reconnaissance: Identify applications that use the Zod library for input validation on array-type fields (e.g., APIs accepting lists of items, batch endpoints). This can be inferred from JavaScript/TypeScript source code, npm dependency manifests, or error message fingerprinting.
  2. Identify a vulnerable endpoint: Find an HTTP endpoint that accepts an array in its request body or query parameters and validates it with a Zod array schema that lacks a .max() or .length() constraint.
  3. Craft a malicious payload: Construct a large JSON array of invalid elements — for example, new Array(10_000_000).fill(5) against a schema like z.number().max(1).array(). The elements must fail validation so that Zod generates one issue object per element.
  4. Submit the request: Send the crafted payload to the target endpoint via an HTTP POST (or appropriate method) with Content-Type: application/json. A single request is sufficient to trigger the condition.
  5. Observe crash: The server process exhausts heap memory allocating issue objects and crashes with an out-of-memory error, resulting in a denial of service (Zod Issue, Github Advisory).

Indicadores de compromisso

  • Logs: Application logs showing sudden process crashes with JavaScript heap out of memory or FATAL ERROR: Reached heap limit Allocation failed errors from the Node.js runtime; access logs showing large POST requests (multi-megabyte bodies) to API endpoints that accept array inputs.
  • Network: Unusually large inbound HTTP request bodies (tens of megabytes or more) targeting a single endpoint in a short time window; repeated requests from the same source IP to array-accepting endpoints.
  • Process: Node.js process terminating unexpectedly with exit code indicating OOM kill (e.g., exit code 137 on Linux); monitoring alerts for sudden spikes in heap memory usage followed by process restart.

Mitigação e soluções alternativas

Update Zod to a version newer than 4.6.5, which includes the abortEarly parse option introduced in PR #6475 that bounds issue accumulation by the schema rather than the input size. As an immediate workaround, add explicit length constraints to all Zod array schemas (e.g., z.array(z.string()).max(1000)) to prevent unbounded input. Additionally, implement request body size limits at the web framework or reverse proxy level (e.g., express.json({ limit: '1mb' })) and consider request timeout mechanisms to reduce exposure (Github Advisory, Zod PR).

Reações da comunidade

The vulnerability was originally raised as a community concern in January 2023 by a developer who noted that Zod's design of reporting all validation errors violates the "secure by default" principle for security-critical applications (Zod Issue). Red Hat tracked the issue with high severity in their Bugzilla system, with 88 users CC'd, indicating broad concern across the Red Hat ecosystem (Red Hat Bugzilla). The fix, implemented by Zod's author Colin McDonnell, underwent multiple rounds of careful review to avoid introducing regressions such as silent data loss or quadratic scan complexity, reflecting the community's attention to correctness alongside security (Zod PR).

Recursos adicionais


Origem: Este relatório foi gerado usando IA

Relacionado Grafana Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-83663HIGH8.7
  • Grafana logoGrafana
  • grafana
NãoSimOct 02, 2026
CVE-2026-94637HIGH8.2
  • Grafana logoGrafana
  • grafana.src
NãoSimOct 02, 2026
CVE-2023-54404HIGH8.2
  • Grafana logoGrafana
  • cockpit-image-builder
NãoNãoOct 01, 2026
CVE-2026-102990HIGH8.2
  • JavaScript logoJavaScript
  • cargo
NãoSimSep 30, 2026
CVE-2026-13720MEDIUM5.4
  • Grafana logoGrafana
  • grafana-selinux
NãoSimSep 30, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades