Unrated severityNVD Advisory· Published Aug 2, 2026
Debian node-axios: axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON…
CVE-2026-67313
Description
axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.
Affected products
1- Range: >=0.28.0
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.