CVE-2026-67313

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.
Configurations

Configuration 1 (hide)

cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-01 13:17

Updated : 2026-09-01 15:40


NVD link : CVE-2026-67313

Mitre link : CVE-2026-67313

CVE.ORG link : CVE-2026-67313


JSON object : View

Products Affected

axios

  • axios
CWE
CWE-400

Uncontrolled Resource Consumption