cvedb.io
CVE-2026-67317
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-01T13:17:01.817 · Last modified 2026-08-01T13:17:01.817

Summary

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and cause uncontrolled network egress or resource exhaustion.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.