High severity7.5NVD Advisory· Published Aug 1, 2026· Updated Sep 1, 2026
CVE-2026-67321
CVE-2026-67321
Description
axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versions
< 24+0.a836cced5-52.1+ 1 more
- (no CPE)range: < 24+0.a836cced5-52.1
- (no CPE)range: >= 0.31.1, < 0.33.0
Patches
Vulnerability mechanics
References
11- github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23nvdExploitVendor Advisory
- github.com/advisories/GHSA-hcpx-6fm6-wx23ghsaADVISORY
- www.vulncheck.com/advisories/axios-before-denial-of-service-via-maxdepth-bypassnvdThird Party Advisory
- github.com/axios/axios/commit/1417285c69344bbcc6420a021f67dee0c6fedb2dghsa
- github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2ghsa
- github.com/axios/axios/pull/11000ghsa
- github.com/axios/axios/pull/11001ghsa
- github.com/axios/axios/releases/tag/v0.33.0ghsa
- github.com/axios/axios/releases/tag/v1.18.0ghsa
- nvd.nist.gov/vuln/detail/CVE-2026-67321ghsa
- nvd.nist.gov/vuln/detail/CVE-2026-69125ghsa
News mentions
0No linked articles in our index yet.