Executive brief
Axios is a popular HTTP client library used in web applications to make network requests. A flaw in how Axios processes form data with deeply nested field names can be exploited by attackers to crash applications by triggering stack overflow errors. This affects server applications that accept untrusted form input and convert it to JSON format, potentially allowing remote denial of service attacks.
Technical details
The formDataToJSON helper in lib/helpers/formDataToJSON.js recursively parses FormData field names into path segments without enforcing a maximum recursion depth. The buildPath() function calls itself recursively once for each bracket-delimited path segment in a field name (e.g., "a[x][x][x]" creates three recursive calls). An attacker-controlled FormData with field names containing thousands of nested brackets can exhaust the V8 JavaScript call stack and throw "RangeError: Maximum call stack size exceeded". The vulnerable code path is reached when: (1) formToJSON() is called directly on attacker-controlled FormData, or (2) axios requests FormData with Content-Type: application/json, triggering the default transformRequest. Axios already applies a maxDepth guard (default 100) to the inverse toFormData() serializer, but formDataToJSON() lacks equivalent protection. The fix involves adding a maximum recursion depth check similar to toFormData().
Affected products
- axios axios >=0.28.0, <1.18.0
Timeline
- 2026-08-01: disclosed
- 2026-08-01: patched: Fixed in version 1.18.0
- 2026-09-01: advisory: Advisory withdrawn as duplicate of GHSA-42h9-826w-cgv3