Axios is vulnerable to DoS attack through lack of data size check
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 1.1%
probabilidad de explotación
1.1%top 39% de las CVE
explotación observada
noninguna fuente lo reporta
Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (`Buffer`/`Blob`) and returns a synthetic 200 response. This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI and cause the process to allocate unbounded memory and crash (DoS), even if the caller requested `responseType: 'stream'`. Versions 0.30.2 and 1.12.0 contain a patch for the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
axios · axiosReferencias
https://github.com/axios/axios/commit/945435fc51467303768202250debb8d4ae892593https://github.com/axios/axios/commit/a1b1d3f073a988601583a604f5f9f5d05a3d0b67https://github.com/axios/axios/commit/c30252f685e8f4326722de84923fcbc8cf557f06https://github.com/axios/axios/pull/7011https://github.com/axios/axios/pull/7034https://github.com/axios/axios/releases/tag/v0.30.2https://github.com/axios/axios/releases/tag/v1.12.0https://github.com/axios/axios/security/advisories/GHSA-4hjh-wcwx-xvwj