Executive brief
Axios, a popular HTTP client library used by thousands of applications, has a flaw in how it validates the depth of nested objects when serializing form data and parameters. An attacker who can control object keys and nested structures passed to Axios can trigger a crash that temporarily disables the affected request processing path, causing a denial of service without exposing or corrupting any data.
Technical details
The vulnerability is a depth-limit bypass in lib/helpers/toFormData.js. When a top-level key ends with '{}', the code calls JSON.stringify() directly on the nested value before the formSerializer.maxDepth guard can validate the structure depth. This allows deeply nested objects to escape the intended ERR_FORM_DATA_DEPTH_EXCEEDED check and instead trigger a native RangeError from JSON.stringify's internal recursion, crashing the process. The attack requires control over both object keys and nested values passed to axios form/parameter serialization functions. The setting formSerializer.metaTokens: false does not mitigate the issue. Patches are available in versions 0.33.0+ and 1.18.0+.
Affected products
- Axios Axios >=0.31.1 <0.33.0, >=1.15.1 <1.18.0
Timeline
- 2026-07-20: disclosed
- 2026-07-20: patched: Patches available in versions 0.33.0+ and 1.18.0+