Junglewise Threat Intelligence

CVE-2026-42037: Axios CRLF injection in multipart form-data blob.type

CVE-2026-42037 · Severity: low · CVSS 3.1 · Published 2026-05-05

Technologies: Axios. Vendors: Axios.

Executive brief

Axios, a popular HTTP client library, contains a flaw in how it handles file uploads via multipart forms. When processing user-provided files with custom MIME types, the library fails to remove line-break characters, allowing attackers to inject false headers into the upload request. This could be exploited in proxy services or file upload systems to confuse servers, bypass content filters, or inject malicious form fields.

Technical details

The vulnerability is a CRLF injection (CWE-93) in lib/helpers/formDataToStream.js at line 27. When a Blob/File-like object is appended to FormData, the value.type property (MIME type) is interpolated directly into the per-part Content-Type header without stripping \r\n sequences. The same codebase sanitizes CRLF in string values but omits this for the blob path, exposing an inconsistency. An attacker who controls blob.type (e.g., via a file upload to a Node.js proxy) can embed \r\n to inject arbitrary headers into the multipart body structure. Since the injection targets the multipart body rather than HTTP request headers, it bypasses Node.js v18+ built-in header protections. The attack is reachable via the standard public API (axios.post with FormData) and requires no special configuration, authentication, or user interaction. Consequences include header spoofing, parser confusion, and potential downstream server exploitation. A fix is available in versions ≥1.15.1, which sanitizes value.type before interpolation.

Affected products

  • axios axios >=1.0.0, <1.15.1

Timeline

  • 2026-04-24: disclosed
  • 2026-05-05: advisory
  • 2026-05-05: patched: Patched in version 1.15.1

References

Related threats