THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67318 — axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrap

[NVD] CVE-2026-67318 — axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrap

mednvdPublished 2026-08-01

CVE-2026-67318 CVSS: None Published: 2026-08-01T13:17:01.947

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axios's byte-counting stream wrapper is gated on maxRedirects === 0, an attacker who contr

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67318