Beveiligingsadvies

CVE-2026-42036

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-24 18:00:33
Laatst bijgewerkt 2026-04-24 18:32:49
Toegewezen door GitHub_M
CVSS-score 5.3
Status PUBLISHED

Beschrijving

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream consumption. This vulnerability is fixed in 1.15.1 and 0.31.1.