Junglewise Threat Intelligence

CVE-2026-67317: axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content

CVE-2026-67317 · Severity: high · CVSS 7.5 · Published 2026-08-01

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a widely-used JavaScript HTTP client library. The fetch adapter—used in browsers, edge runtimes, and Node.js—fails to enforce the maxBodyLength limit when uploading data as a WHATWG ReadableStream whose size cannot be determined in advance. An attacker who can control the stream data can send payloads larger than the application's configured limit, causing unexpected bandwidth consumption, resource exhaustion, and potential API quota depletion on upstream services.

Technical details

The vulnerability is a logic gap in lib/adapters/fetch.js: the getBodyLength() function lacks a handler for ReadableStream objects, causing it to return undefined when no finite Content-Length header is present. The maxBodyLength validation only triggers if the resolved body length is a finite number; for unknown-length streams, the check is skipped entirely. The in-flight trackStream() wrapper (used when onUploadProgress is enabled) only reports progress and does not enforce byte limits. The HTTP adapter correctly enforces maxBodyLength by chunk-counting and rejection. Affected versions are ≥1.7.0 (when the fetch adapter was introduced); exploitation requires an application to pass attacker-controlled ReadableStream data to axios and rely on maxBodyLength as the sole guard. Patched in version 1.18.0.

Affected products

  • Axios Axios >=1.7.0, <1.18.0

Timeline

  • 2026-07-20: disclosed
  • 2026-07-06: patched: Version 1.18.0+

References

Related threats