Cyber Security News

ZAP JavaScript Engine Memory Leak Issue Impacts Active Scan Usage

The ZAP (Zed Attack Proxy) project, a widely used open-source web application security scanner, has disclosed a critical memory leak in its JavaScript engine.

This flaw, likely present for some time, now disrupts active scanning workflows following the introduction of a new JavaScript scan rule in the OpenAPI add-on.

Security teams relying on ZAP for dynamic application security testing (DAST) face potential denial-of-service-like conditions during scans.

ZAP maintainers issued the alert on January 28, 2026, emphasizing urgent remediation efforts. The memory leak manifests during active scans, where the JavaScript engine fails to properly deallocate resources, leading to rapid memory exhaustion.

This issue gained prominence after the OpenAPI add-on’s recent update incorporated the problematic JS scan rule, amplifying resource consumption in automated testing pipelines.

At its core, the vulnerability stems from inefficient memory handling within ZAP’s JavaScript engine, possibly tied to long-running script executions or unhandled garbage collection in scan rules.

Active scans ZAP’s hallmark feature for probing web apps via automated attacks like SQL injection and XSS trigger the leak when processing OpenAPI specifications with embedded JavaScript logic.

Impacts include:

  • Crashes or hangs in scanning sessions, halting vulnerability discovery.
  • Elevated resource usage on scanning hosts, risking broader infrastructure strain in CI/CD environments.
  • Delayed security assessments for DevSecOps teams using ZAP in Docker or standalone deployments.

The flaw does not expose scanned applications to exploits but undermines ZAP’s reliability as a security tool, potentially delaying patch identification in production-like environments.

Mitigation and Release Updates

To curb immediate risks, the OpenAPI add-on has been patched to disable the offending JS scan rule by default. Users must update to the latest version for this workaround. Nightly and weekly ZAP releases are now available with the fix, alongside refreshed Docker images for weekly and live channels.

Release TypeStatusUpdate Advice
NightlyUpdatedPull latest for testing
WeeklyUpdatedRecommended for production scans
Docker (Weekly/Live)UpdatedRebuild containers promptly
StablePendingMonitor for underlying fix

Developers should verify installations via zaproxy –version and re-enable the rule only post-root fix.

ZAP maintainers are prioritizing a permanent resolution to the JavaScript engine leak, with ongoing commits expected soon. This incident underscores the challenges of integrating dynamic scripting in security tools, where performance bugs can cascade into operational vulnerabilities.

Security professionals are advised to monitor ZAP’s GitHub repository and announcements for the stable release. In the interim, fallback to passive scans or alternative tools like Burp Suite may bridge gaps.

Recently he Zed Attack Proxy (ZAP) team has released the OWASP PTK add-on, version 0.2.0 alpha, integrating the OWASP Penetration Testing Kit (PTK) browser extension directly into ZAP-launched browsers.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago