๐Ÿ” CVE Alert

CVE-2026-42039

UNKNOWN 0.0

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.

CWE CWE-674
Vendor axios
Product axios
Published Apr 24, 2026
Last Updated Apr 24, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
>= 1.0.0, < 1.15.1 < 0.31.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-62hf-57xw-28j9