VYPR
Unrated severityNVD Advisory· Published Aug 2, 2026

Debian node-axios: axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON…

CVE-2026-67313

Description

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.