CVE-2026-67321Disclosure(axios / axios)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-01: 2Technical Details · 2026-08-01: 208-01
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-67321 axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control obje… https://www.cve.org/CVERecord?id=CVE-2026-67321

    Post summary

    The CVE‑2026‑67321 entry describes an incomplete depth‑limit bypass in axios's toFormData.js, but no proof of concept, exploit code, patch, or active exploitation details are provided.

    000201.3K
    58.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-67321 axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control obje… https://www.cve.org/CVERecord?id=CVE-2026-67321 ----- Traducción: CVE-2026-67321 axi… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-67321, detailing an incomplete depth‑limit bypass in axios’s toFormData.js, but offers no PoC, exploit, patch, or active usage information.

    0000049
    96 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more