
PEACH
Uma estrutura de isolamento de inquilino
CVE-2023-54404 is an uncontrolled resource consumption (Denial of Service) vulnerability in the Zod schema-validation library affecting all versions through 4.6.5. An unauthenticated remote attacker can exhaust the memory of an application by submitting a large array to any endpoint that validates input using a Zod array schema without a length constraint. The vulnerability was originally reported as a GitHub issue in January 2023 and formally disclosed in October 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (Github Advisory, Red Hat Bugzilla).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in the handleArrayResult parse logic of the $ZodArray class. When Zod validates an array, it accumulates one validation issue object per failing element with no cap, early-exit mechanism, or maximum issue count. Submitting a very large array (e.g., new Array(10_000_000).fill(invalidValue)) causes the Node.js process to allocate millions of issue objects, exhausting available heap memory and crashing the process. The issue was first raised publicly in GitHub Issue #1872, and the fix was implemented via PR #6475, which introduced an abortEarly parse option that stops validation at the first aborting error in each container loop (Github Advisory, Zod Issue, Zod PR).
Successful exploitation results in a complete availability impact — the targeted application process crashes due to out-of-memory conditions, causing a denial of service. There is no confidentiality or integrity impact; the vulnerability cannot be used to read or modify data. Any application that exposes a network-accessible endpoint performing Zod array validation without explicit length constraints is at risk, and a single malicious request can bring down the service (Github Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, reflecting a currently low probability of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Despite the lack of a formal PoC, the attack technique is straightforward and requires no authentication, privileges, or user interaction — any attacker who can send an HTTP request to a vulnerable endpoint can trigger the condition (Github Advisory).
.max() or .length() constraint.new Array(10_000_000).fill(5) against a schema like z.number().max(1).array(). The elements must fail validation so that Zod generates one issue object per element.Content-Type: application/json. A single request is sufficient to trigger the condition.JavaScript heap out of memory or FATAL ERROR: Reached heap limit Allocation failed errors from the Node.js runtime; access logs showing large POST requests (multi-megabyte bodies) to API endpoints that accept array inputs.Update Zod to a version newer than 4.6.5, which includes the abortEarly parse option introduced in PR #6475 that bounds issue accumulation by the schema rather than the input size. As an immediate workaround, add explicit length constraints to all Zod array schemas (e.g., z.array(z.string()).max(1000)) to prevent unbounded input. Additionally, implement request body size limits at the web framework or reverse proxy level (e.g., express.json({ limit: '1mb' })) and consider request timeout mechanisms to reduce exposure (Github Advisory, Zod PR).
The vulnerability was originally raised as a community concern in January 2023 by a developer who noted that Zod's design of reporting all validation errors violates the "secure by default" principle for security-critical applications (Zod Issue). Red Hat tracked the issue with high severity in their Bugzilla system, with 88 users CC'd, indicating broad concern across the Red Hat ecosystem (Red Hat Bugzilla). The fix, implemented by Zod's author Colin McDonnell, underwent multiple rounds of careful review to avoid introducing regressions such as silent data loss or quadratic scan complexity, reflecting the community's attention to correctness alongside security (Zod PR).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."