CVE-2026-67317
axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.
| CWE | CWE-770 |
| Vendor | axios |
| Product | axios |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for axios axios
Be the first to know when new unknown vulnerabilities affecting axios axios are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
axios / axios
1.7.0 < 1.18.0
References
Credits
๐ asadeddin