CVE-2026-67321
- EPSS 0.29%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 16:16:30
axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios fo...
CVE-2026-67319
- EPSS 0.26%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 19:16:51
axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a nu...
CVE-2026-67318
- EPSS 0.36%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 20:17:26
axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axi...
CVE-2026-67316
- EPSS 0.26%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 16:16:30
axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), a...
CVE-2026-67315
- EPSS 0.29%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 17:16:41
axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through c...
CVE-2026-67312
- EPSS 0.34%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 03.08.2026 19:16:50
axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an applicat...
CVE-2026-67320
- EPSS 0.3%
- Veröffentlicht 01.08.2026 12:22:17
- Zuletzt bearbeitet 03.08.2026 17:16:41
axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immut...
CVE-2026-67317
- EPSS 0.36%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 03.08.2026 19:16:51
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and ...
CVE-2026-67314
- EPSS 0.37%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 03.08.2026 19:16:51
axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primi...
CVE-2026-67313
- EPSS 0.34%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 03.08.2026 20:17:26
axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhau...