Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 03 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion. | |
| Title | axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream | |
| First Time appeared |
Axios
Axios axios |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Axios
Axios axios |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-03T18:25:21.446Z
Reserved: 2026-07-29T13:06:35.179Z
Link: CVE-2026-67317
Updated: 2026-08-03T18:24:51.913Z
Status : Received
Published: 2026-08-01T13:17:01.817
Modified: 2026-08-03T19:16:51.243
Link: CVE-2026-67317
OpenCVE Enrichment
Updated: 2026-08-03T09:45:04Z