{"id":"GHSA-5c9x-8gcm-mpgx","summary":"Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0","details":"### Summary\n\nFor stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits.\n\n### Details\n\nRelevant flow in lib/adapters/http.js:\n  - 556-564: maxBodyLength check applies only to buffered/non-stream data.\n  - 681-682: maxRedirects === 0 selects native http/https transport.\n  - 694-699: options.maxBodyLength is set, but native transport does not enforce it.\n  - 925-945: stream is piped directly to socket (data.pipe(req)) with no Axios byte counting.\n\nThis creates a path-specific bypass for streamed uploads.\n\n  ### PoC\n\nEnvironment:\n\n  - Axios main at commit f7a4ee2\n  - Node v24.2.0\n\n  Steps:\n  1. Start an HTTP server that counts uploaded bytes and returns {received}.\n  2. Send a 2 MiB Readable stream with:\n      - adapter: 'http'\n      - maxBodyLength: 1024\n      - maxRedirects: 0\n\n  Observed:\n  - Request succeeds; server reports received: 2097152.\n\n  Control checks:\n  - Same stream with default/nonzero redirects: rejected with ERR_FR_MAX_BODY_LENGTH_EXCEEDED.\n  - Buffered body with maxRedirects: 0: rejected with ERR_BAD_REQUEST.\n\n  ### Impact\nType: DoS / uncontrolled upstream upload / resource exhaustion.\nImpacted: Node.js services using streamed request bodies with maxBodyLength expecting hard enforcement, especially when following Axios guidance to use maxRedirects: 0 for streams.","aliases":["CVE-2026-42034"],"modified":"2026-07-17T21:14:14.560278865Z","published":"2026-05-05T00:33:25Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-05T00:33:25Z","nvd_published_at":"2026-04-24T18:16:30Z","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://github.com/axios/axios/security/advisories/GHSA-5c9x-8gcm-mpgx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42034"},{"type":"PACKAGE","url":"https://github.com/axios/axios"}],"affected":[{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"1.15.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5c9x-8gcm-mpgx/GHSA-5c9x-8gcm-mpgx.json"}},{"package":{"name":"axios","ecosystem":"npm","purl":"pkg:npm/axios"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.31.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.31.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5c9x-8gcm-mpgx/GHSA-5c9x-8gcm-mpgx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}