Junglewise Threat Intelligence

CVE-2025-58754: Axios denial of service via data URI memory exhaustion

CVE-2025-58754 · Severity: low · CVSS 3.1 · Published 2025-09-11

Technologies: Axios. Vendors: Axios.

Executive brief

Axios, a widely-used HTTP client library for Node.js and browsers, fails to enforce memory limits when decoding data: scheme URLs. An attacker can craft a malicious data: URL containing a very large Base64-encoded payload, causing the Node.js process to allocate unbounded memory and crash. This affects applications that accept URLs from untrusted sources, even if they configure strict memory limits via maxContentLength or maxBodyLength settings.

Technical details

The vulnerability exists in Axios's Node.js HTTP adapter (lib/adapters/http.js) and the fromDataURI helper (lib/helpers/fromDataURI.js). When the adapter encounters a URL with the data: scheme, it bypasses normal HTTP processing and calls fromDataURI() to decode the Base64 payload directly into a Buffer or Blob. The decoder does not honor maxContentLength or maxBodyLength configuration options—these are only applied to HTTP stream responses. An attacker supplies a data: URL with a massive Base64-encoded payload, causing Buffer.from() to allocate the entire decoded content into memory at once. On memory-constrained systems, this causes heap exhaustion and process termination (DoS). Patches released in versions 1.12.0 and 0.30.0 add pre-decode size estimation and enforce maxContentLength checks for data: URIs, rejecting oversized payloads before allocation.

Affected products

  • axios axios <1.11.0 and <0.29.0

Timeline

  • 2025-09-11: disclosed: Advisory GHSA-4hjh-wcwx-xvwj published; CVE-2025-58754 assigned
  • 2025-09-10: patched: Patch merged in PR #7011 for v1.x branch (version 1.12.0)
  • 2025-09-16: patched: Backport patch merged in PR #7034 for v0.x branch (version 0.30.0)

References

Related threats