Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-67313

Опубликовано: 01 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

РелизСтатусПримечание
devel

not-affected

1.18.0-1
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

released

1.18.0-1

Показывать по

EPSS

Процентиль: 27%
0.00338
Низкий

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 месяца назад

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

nvd
около 1 месяца назад

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

debian
около 1 месяца назад

axios versions 0.28.0 and later contain uncontrolled recursion in form ...

github
около 1 месяца назад

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

CVSS3: 5.3
fstec
около 2 месяцев назад

Уязвимость функции formDataToJSON() файла lib/helpers/formDataToJSON.js библиотеки axios, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00338
Низкий