cbcvebase.
CVE-2026-42039
published 2026-04-24

CVE-2026-42039: Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit…

medium6.9CVSS 4.0
AVNACLATNPRNUINVCNVINVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp2system-rhel7
3scale-amp2system-rhel8
3scale-amp2system-rhel9
3scale-amp21system
3scale-amp22system
advanced-cluster-securityrhacs-main-rhel8
ansible-automation-platform-26gateway-rhel9
ansible-automation-platformautomation-dashboard-rhel9
ansible-automation-platformautomation-portal
apicurioapicurio-registry-ui-rhel8
apicurioapicurio-registry-ui-rhel9
axiosaxios< 0.31.10.31.1
axiosaxios
axiosaxios
axiosaxios>= 0 < 0.31.10.31.1
axiosaxios>= 1.0.0 < 1.15.11.15.1
axiosaxios>= 1.0.0 < 1.15.11.15.1
boostboost
container-native-virtualizationkubevirt-console-plugin
container-native-virtualizationkubevirt-console-plugin-rhel9
devspacescode-rhel9
devspacesdashboard-rhel9
discoverydiscovery-ui-rhel9
gatekeepergatekeeper-rhel9
grafanagrafana