MaxBodyLength Bypass Vulnerability in Axios by Axios
CVE-2026-67317
6.3MEDIUM
What is CVE-2026-67317?
The vulnerability affects Axios versions prior to 1.18.0, allowing attackers to bypass upload size restrictions by supplying unknown-length data via WHATWG ReadableStream in situations where Content-Length cannot be determined. This flaw can lead to potential uncontrolled network egress and resource exhaustion, compromising system stability and performance.
Affected Version(s)
axios 1.7.0 < 1.18.0
axios 1.18.0
