
CVE-2026-67321 axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control obje… https://www.cve.org/CVERecord?id=CVE-2026-67321
Post summary
The CVE‑2026‑67321 entry describes an incomplete depth‑limit bypass in axios's toFormData.js, but no proof of concept, exploit code, patch, or active exploitation details are provided.

