Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67321

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

A flaw was found in axios. A remote attacker could exploit an incomplete depth-limit bypass when the component serializes objects with specific top-level keys. By manipulating object keys and nested values during form or parameter serialization, an attacker can trigger a processing error. This can lead to a denial of service, making the affected request path unavailable to legitimate users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-ui-rhel9Affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf4-rhel9Affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf5-rhel9Affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-hub-ui-rhel9Affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Affected
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel9Affected
Red Hat Ansible Automation Platform 2automation-gatewayWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2510011axios: axios: Denial of Service via object serialization bypass

EPSS

Процентиль: 21%
0.00291
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

nvd
около 1 месяца назад

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

debian
около 1 месяца назад

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...

github
около 1 месяца назад

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

CVSS3: 5.3
fstec
около 2 месяцев назад

Уязвимость модуля lib/helpers/toFormData.js библиотеки axios, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00291
Низкий

7.5 High

CVSS3