VDB
CVE-2026-67313
CVE-2026-67313
PUBLISHED
CVSS 6.3 MEDIUM
Reported by VulnCheck · Published August 1, 2026
axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.
Risk Scores
CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| axios | axios | 0.28.0, 1.18.0 |
| chainguard | langfuse-3 | 0, 0, 0 |
| chainguard | kibana-9.1 | 0, 0, 0 |
| chainguard | nextcloud-server-31 | 0, 0, 0 |
| chainguard | arangodb-3.11 | 0, 0 |
| chainguard | gitlab-rails-ce-19.3 | 0, 0 |
| chainguard | opensearch-dashboards-2 | 0, 0, 0 |
| wolfi | nextcloud-server-32 | 0, 0, 0 |
| chainguard | kibana-9.4 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.2 | 0, 0 |
| chainguard | opensearch-dashboards-3-fips | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-19.1 | 0, 0 |
| chainguard | langfuse-fips-3 | 0, 0, 0 |
| chainguard | kubeflow-centraldashboard | 0, 0, 0 |
| wolfi | langfuse-3 | 0, 0, 0 |
| wolfi | opensearch-dashboards-3 | 0, 0, 0 |
| chainguard | jitsucom-jitsu | 0, 0, 0 |
| chainguard | opensearch-dashboards-3 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-19.1 | 0, 0 |
| wolfi | lerna | 0, 0, 0 |
…and 27 more
Timeline
- Jul 20, 2026 CVE Published
- Aug 1, 2026 Coalition ESS Score
- Aug 2, 2026 EPSS Score
- Aug 3, 2026 Security Advisory
- Aug 3, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 2, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-42h9-826w-cgv3) vendor-advisory
- VulnCheck Advisory: axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON third-party-advisory