Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security vulnerability in zod@3.22.2 #2828

Closed
syukronarie opened this issue Oct 2, 2023 · 6 comments
Closed

Security vulnerability in zod@3.22.2 #2828

syukronarie opened this issue Oct 2, 2023 · 6 comments

Comments

@syukronarie
Copy link

Hi maintainers,

I am reporting a security vulnerability in zod.
Vulnerability type: Regular Expression Denial of Service (ReDoS) [High Severity]
Additional information: https://security.snyk.io/vuln/SNYK-JS-ZOD-5925617
image

Best regards,
Arie

@matjaeck
Copy link

matjaeck commented Oct 2, 2023

This is -- there is no other way to say it -- just another snyk bullshit report.

It's not even involving any code from this package.

Pure bullshit.

@BluDood
Copy link

BluDood commented Oct 2, 2023

This is -- there is no other way to say it -- just another snyk bullshit report.

It's not even involving any code from this package.

Pure bullshit.

@matjaeck Explain? Looking at the report and the included video shows that it does take significantly longer to process - I'll verify if this is the case tomorrow

@tylerd-canva
Copy link

probably a duplicate of #2787

@Phoenix-Alpha
Copy link

GHSA-m95q-7qp3-xv42

@BluDood
Copy link

BluDood commented Oct 3, 2023

I decided to make some tests in StackBlitz - and in my testing, only 3.22.0+ are vulnerable.
3.22.0+: https://stackblitz.com/edit/stackblitz-starters-hmvyja?file=index.js
3.21.4: https://stackblitz.com/edit/stackblitz-starters-d7stxv?file=index.js
Same results as #2787.
Also there are like 5 different issues talking about this now, should we merge them into one?

@colinhacks
Copy link
Owner

Fixed by #2824

Landed in Zod v3.22.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants