
🚨High - Zod Array Validation Memory Exhaustion DoS (CVE-2023-54404) Zod’s $ZodArray handleArrayResult parsing logic accumulates issues for every failing element when validating arrays without a max length constraint. An attacker can submit an extremely large array to trigger unbounded issue collection and exhaust memory, crashing the process (OOM). Arrays with explicit length/max constraints are not impacted. 👉Affected: zod <= 4.6.5
