logo

CVE-2026-44488: Axios Fetch Adapter Ignores Configured Request and Response Size Limits

ID: 4523a516-f7bf-5daf-b03a-2d0378f5ea52

STIX ID: report--4523a516-f7bf-5daf-b03a-2d0378f5ea52

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

...
...

A high-severity vulnerability (CVE-2026-44488, CVSS 7.5) in Axios 1.7.0–1.15.x causes the fetch adapter to ignore maxContentLength and maxBodyLength settings, allowing arbitrarily large payloads that can lead to memory exhaustion and denial of service; upgrade to Axios 1.16.0+ or force the http adapter/implement application-level size checks as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.