Skip to content
CVE-2023-54404: High-Risk Memory Exhaustion Vulnerability in Zod Library

CVE-2023-54404: High-Risk Memory Exhaustion Vulnerability in Zod Library

First seen 2 Oct 2026, 01:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 02:07 UTC
  • •CVE-2023-54404 allows memory exhaustion via oversized arrays in Zod library.
  • •High operational risk for internet-facing APIs using Zod for validation.
  • •No active exploitation reported; mitigation includes capping request sizes.

A vulnerability identified as CVE-2023-54404 in the Zod schema-validation library version 4.6.5 allows attackers to exploit uncontrolled resource consumption by submitting oversized arrays. This can lead to memory exhaustion and application crashes, particularly affecting internet-facing APIs and web backends that validate user-controlled arrays. The flaw does not currently show signs of active exploitation, but it poses a high operational risk, especially for services without constraints on array sizes. Users are advised to monitor for unusually large array submissions and implement limits on request sizes until a fix is confirmed. The vulnerability was published on October 1, 2026, with a CVSS score of 8.2, indicating a high severity level. Mitigation strategies include capping request sizes and implementing early termination for validation errors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
CVE-2023-54404 published
The vulnerability in Zod library version 4.6.5 was disclosed, allowing memory exhaustion through oversized arrays.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2023-54404 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of Zod are affected?
The vulnerability affects Zod library version 4.6.5.
Is there a patch available?
No vendor-confirmed fix has been released yet for CVE-2023-54404.
What should I do to mitigate this risk?
Implement limits on request and array sizes, and monitor for unusually large submissions.