Junglewise Threat Intelligence

Axios HTTP/2 streamed uploads bypass maxBodyLength

Severity: low · CVSS 3.1 · Published 2026-08-01

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a popular JavaScript HTTP client library used by applications to make web requests. When configured with a size limit (maxBodyLength) for outbound requests sent over HTTP/2 protocol with streamed data, Axios fails to enforce this limit, allowing attackers who control the data stream to cause the application to send more data than permitted. The impact is limited to excess bandwidth consumption and policy violations, but does not enable unauthorized access or code execution.

Technical details

The vulnerability is a policy-bypass issue in Axios's Node.js HTTP adapter (lib/adapters/http.js) where HTTP/2 transport selection is unconditional and does not invoke the byte-counting stream wrapper that enforces maxBodyLength. The wrapper is currently gated on maxBodyLength > -1 && maxRedirects === 0, which means HTTP/2 requests with default redirect settings bypass this protection. An attacker controlling a stream passed to axios (e.g., via an upload endpoint proxying user data) can transmit arbitrarily larger bodies than the configured maxBodyLength, verified in testing with a 1024-byte limit transmitting 2 MB. The vulnerability requires all of: Node.js HTTP adapter, httpVersion: 2, streamed request data, and a finite maxBodyLength. Buffered request bodies and browser adapters are unaffected. Patched in version 1.18.0 and later; workaround for 1.15.1+ is to set maxRedirects: 0.

Affected products

  • Axios Axios >=1.13.0, <1.18.0

Timeline

  • 2026-07-06: disclosed: Original advisory published on GitHub
  • 2026-08-01: patched: Patched in version 1.18.0
  • 2026-08-01: advisory: OSV/GHSA advisory published

References

Related threats