CVE-2026-67317

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-01 13:17

Updated : 2026-09-01 15:39


NVD link : CVE-2026-67317

Mitre link : CVE-2026-67317

CVE.ORG link : CVE-2026-67317


JSON object : View

Products Affected

axios

  • axios
CWE
CWE-770

Allocation of Resources Without Limits or Throttling