Bug 2509989 (CVE-2026-67318)
| Summary: | CVE-2026-67318 axios: axios: Denial of Service due to maxBodyLength bypass in HTTP/2 requests | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anthomas, aruklets, dbosanac, dfreiber, dkeler, doconnor, drow, dschmidt, dymurray, ehelms, ewittman, ggainey, gparvin, ibolton, janstey, jburrell, jlanda, jmatthew, jmontleo, jpasqual, jreimann, juwatts, kaycoth, kshier, mdellweg, mdessi, mhulan, mrizzi, nipatil, nmoumoul, osousa, pantinor, pcattana, pcreech, pgaikwad, prwatson, rchan, rhaigner, rjohnson, rkubis, sdawley, simaishi, slucidi, smallamp, sseago, stcannon, suppawar, teagle, thason, tmalecek, vkumar, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in axios, a popular JavaScript library for making HTTP requests. When using the Node.js HTTP/2 adapter, axios fails to properly enforce the configured maxBodyLength limit for streamed request bodies. This allows a remote attacker, by controlling the input stream, to send an arbitrarily large amount of data. The primary impact is excessive resource consumption, increased network egress, and potential denial of service for the affected application.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-01 13:02:00 UTC
|