Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-39j5-w47m-2gmv

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

EPSS

Процентиль: 29%
0.00359
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-770

Связанные уязвимости

nvd
2 дня назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

debian
2 дня назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for W ...

EPSS

Процентиль: 29%
0.00359
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-770