ZAP JavaScript Engine Memory Leak Issue Impacts Active Scan Usage
ID: eabfa5a2-34f1-5c2f-8866-0a66680d9596
STIX ID: report--eabfa5a2-34f1-5c2f-8866-0a66680d9596
Feed Name: cybersecurityNews.com
Threat Score
ZAP disclosed a critical memory leak in its JavaScript engine that surfaced after an OpenAPI add-on introduced a problematic JS scan rule; active scans can rapidly exhaust memory, causing crashes or hangs and disrupting DAST/CI-CD pipelines. The OpenAPI add-on has been patched to disable the rule by default and nightly/weekly releases and updated Docker images are available; a permanent fix is pending and users are advised to update and monitor ZAP’s repository.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
