Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-67321

Опубликовано: 01 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

РелизСтатусПримечание
devel

not-affected

1.18.0-1
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

needs-triage

upstream

released

1.18.0-1

Показывать по

EPSS

Процентиль: 21%
0.00291
Низкий

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 месяца назад

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

nvd
около 1 месяца назад

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

debian
около 1 месяца назад

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...

github
около 1 месяца назад

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

CVSS3: 5.3
fstec
около 2 месяцев назад

Уязвимость модуля lib/helpers/toFormData.js библиотеки axios, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00291
Низкий