cbcvebase.
CVE-2026-42034
published 2026-04-24

CVE-2026-42034: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits. This vulnerability is fixed in 1.15.1 and 0.31.1.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp2system-rhel7
3scale-amp2system-rhel8
3scale-amp2system-rhel9
3scale-amp21system
3scale-amp22system
advanced-cluster-securityrhacs-main-rhel8
ansible-automation-platform-26gateway-rhel9
ansible-automation-platformautomation-dashboard-rhel9
ansible-automation-platformautomation-portal
apicurioapicurio-registry-ui-rhel8
apicurioapicurio-registry-ui-rhel9
axiosaxios< 0.31.10.31.1
axiosaxios
axiosaxios
axiosaxios>= 0 < 0.31.10.31.1
axiosaxios>= 1.0.0 < 1.15.11.15.1
axiosaxios>= 1.0.0 < 1.15.11.15.1
boostboost
container-native-virtualizationkubevirt-console-plugin
container-native-virtualizationkubevirt-console-plugin-rhel9
devspacescode-rhel9
devspacesdashboard-rhel9
discoverydiscovery-ui-rhel9
gatekeepergatekeeper-rhel9
grafanagrafana