<Vulnerability name="CVE-2026-67313">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-01T12:22:16</PublicDate>
    <Bugzilla id="2510017" url="https://bugzilla.redhat.com/show_bug.cgi?id=2510017" xml:lang="en:us">
axios: axios: Denial of Service via uncontrolled recursion in formDataToJSON
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-674</CWE>
    <Details xml:lang="en:us" source="Mitre">
axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in axios. A remote attacker could exploit an uncontrolled recursion vulnerability in the formDataToJSON function by supplying FormData with field names containing deeply nested bracket segments. This could exhaust the JavaScript call stack, leading to a RangeError and causing a denial of service (DoS) through request failure or process termination in affected applications.
    </Details>
    <AffectedRelease impact="important" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-07-30T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:48758">RHSA-2026:48758</Advisory>
        <Package name="jaeger-main">jaeger-main-2.20.0-0.8.hum1</Package>
    </AffectedRelease>
    <AffectedRelease impact="important" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-08-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:49714">RHSA-2026:49714</Advisory>
        <Package name="grafana13-1-main">grafana13-1-main-13.1.1-0.5.hum1</Package>
    </AffectedRelease>
    <AffectedRelease impact="important" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-08-05T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:50826">RHSA-2026:50826</Advisory>
        <Package name="grafana13-1-main">grafana13-1-main-13.1.1-0.5.2.hum1</Package>
    </AffectedRelease>
    <PackageState impact="important" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>grafana12.4</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-67313
https://nvd.nist.gov/vuln/detail/CVE-2026-67313
https://github.com/axios/axios/security/advisories/GHSA-42h9-826w-cgv3
https://www.vulncheck.com/advisories/axios-before-denial-of-service-via-formdatatojson
    </References>
</Vulnerability>