MEDIUMCVSS 6.9
GHSA-3mcp-22mf-vrw3
Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken
Summary
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-hcpx-6fm6-wx23. This link is maintained to preserve external references. ## Original Description axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| npm | axios | — | — |
Remediation: No patched version is listed by GitHub.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.