HIGH
CVE-2026-67317
CVSS
7.5
Description
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.5%
Probability of exploitation in next 30 days
41.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.