Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-67317

Опубликовано: 01 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

РелизСтатусПримечание
devel

not-affected

1.18.0-1
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

released

1.18.0-1

Показывать по

EPSS

Процентиль: 29%
0.00359
Низкий

Связанные уязвимости

CVSS3: 5.3
redhat
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

nvd
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

debian
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for W ...

github
около 1 месяца назад

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

CVSS3: 5.8
fstec
около 2 месяцев назад

Уязвимость адаптера fetch библиотеки axios, позволяющая нарушителю оказать воздействие на доступность защищаемой информации

EPSS

Процентиль: 29%
0.00359
Низкий