A AegiFlow
MEDIUMCVSS 6.9

GHSA-3mcp-22mf-vrw3

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Published
2026-08-01
Modified
2026-09-08
Sources
github-advisory

Summary

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-hcpx-6fm6-wx23. This link is maintained to preserve external references. ## Original Description axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmaxios

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.