๐Ÿ” CVE Alert

CVE-2026-67317

UNKNOWN 0.0

axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

CWE CWE-770
Vendor axios
Product axios
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
1.7.0 < 1.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-jqh4-m9w3-8hp9 vulncheck.com: https://www.vulncheck.com/advisories/axios-before-maxbodylength-bypass-via-readablestream

Credits

๐Ÿ” asadeddin