Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42039

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.

A flaw was found in Axios, a promise-based HTTP client for browsers and Node.js. This vulnerability occurs because the toFormData function recursively processes nested objects without a depth limit. A remote attacker can exploit this by sending deeply nested request data, which causes the Node.js process to crash due to a RangeError, leading to a potential Denial of Service (DoS) if the process crashes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4axiosNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel8Affected
Migration Toolkit for Applications 8mta/mta-ui-rhel9Affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-compat-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel9Affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-operator-bundleNot affected
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9-operatorNot affected
Red Hat 3scale API Management Platform 23scale-amp21/systemNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2461630axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data

EPSS

Процентиль: 50%
0.00717
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.

CVSS3: 7.5
nvd
4 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.

CVSS3: 7.5
debian
4 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. Prio ...

CVSS3: 7.5
github
3 месяца назад

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

EPSS

Процентиль: 50%
0.00717
Низкий

7.5 High

CVSS3