CVE-2026-67321Medium· 7.5▾ Sunlitaxios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serializati…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.4%
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
7.5 → —
— → 7.5
axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
axios >= 0.31.1, < 0.33.0axios >= 1.15.1, < 1.18.0Patched in:
axios 0.33.0axios 1.18.0Source: https://github.com/advisories/GHSA-hcpx-6fm6-wx23
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
GHSA-3mcp-22mf-vrw3Medium· 7.5Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken
GHSA-jqh4-m9w3-8hp9MediumAxios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
GHSA-hcpx-6fm6-wx23MediumAxios form serializer maxDepth bypass via {} metatoken
GHSA-pmv8-rq9r-6j72MediumAxios: Deep formToJSON Key Recursion Can Cause Denial of Service
GHSA-42h9-826w-cgv3MediumAxios: Excessive recursion in formDataToJSON can cause denial of service
CVE-2026-73566High· 7.5node-tar is a tar archive manipulation library for Node.js