VDB
CVE-2026-67317
CVE-2026-67317
PUBLISHED
CVSS 6.3 MEDIUM
Reported by VulnCheck · Published August 1, 2026
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.
Risk Scores
CVSS 4.0
6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| axios | axios | 1.7.0, 1.18.0 |
| chainguard | nextcloud-server-33 | 0, 0, 0 |
| wolfi | jitsucom-jitsu | 0, 0, 0 |
| chainguard | langfuse-3 | 0, 0, 0 |
| wolfi | nextcloud-server-33 | 0, 0, 0 |
| chainguard | nextcloud-server-34 | 0, 0, 0 |
| chainguard | langfuse-2 | 0, 0, 0 |
| chainguard | kibana-9.2 | 0, 0, 0 |
| chainguard | kibana-9.1 | 0, 0, 0 |
| chainguard | opensearch-dashboards-2 | 0, 0, 0 |
| chainguard | nextcloud-server-32 | 0, 0, 0 |
| chainguard | jitsucom-jitsu | 0, 0, 0 |
| chainguard | lerna | 0, 0, 0 |
| chainguard | opensearch-dashboards-3-fips | 0, 0, 0 |
| wolfi | kubeflow-centraldashboard | 0, 0, 0 |
| chainguard | opensearch-dashboards-3 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-19.3 | 0, 0 |
| chainguard | wazuh-dashboard | 0, 0 |
| chainguard | semaphore | 0, 0 |
| chainguard | kibana-9.3 | 0, 0, 0 |
…and 25 more
Timeline
- Jul 20, 2026 CVE Published
- Aug 1, 2026 Coalition ESS Score
- Aug 2, 2026 EPSS Score
- Aug 3, 2026 Security Advisory
- Aug 27, 2026 EPSS Score
- Aug 31, 2026 EPSS Score
- Sep 2, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-jqh4-m9w3-8hp9) vendor-advisory
- VulnCheck Advisory: axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream third-party-advisory