๐Ÿ” CVE Alert

CVE-2026-67321

UNKNOWN 0.0

axios before 0.33.0 Denial of Service via maxDepth bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

CWE CWE-674
Vendor axios
Product axios
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
0.31.1 < 0.33.0
axios / axios
1.15.1 < 1.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23 vulncheck.com: https://www.vulncheck.com/advisories/axios-before-denial-of-service-via-maxdepth-bypass

Credits

๐Ÿ” fg0x0