Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67317

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

A flaw was found in axios. This vulnerability allows a remote attacker to bypass configured upload size limits by supplying unknown-length stream data when using WHATWG ReadableStream request bodies in the fetch adapter, specifically when the Content-Length cannot be determined. This can lead to uncontrolled network egress or resource exhaustion, resulting in a Denial of Service (DoS) for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf4-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf5-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel8Fix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-ossmc-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/kiali-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2510031axios: axios: Denial of Service via maxBodyLength bypass with ReadableStream

EPSS

Процентиль: 29%
0.00359
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

nvd
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

debian
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for W ...

github
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

CVSS3: 5.8
fstec
около 2 месяцев назад

Уязвимость адаптера fetch библиотеки axios, позволяющая нарушителю оказать воздействие на доступность защищаемой информации

EPSS

Процентиль: 29%
0.00359
Низкий

5.3 Medium

CVSS3