{
  "threat_severity" : "Important",
  "public_date" : "2026-08-01T12:22:18Z",
  "bugzilla" : {
    "description" : "axios: axios: Denial of Service via object serialization bypass",
    "id" : "2510011",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2510011"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-770",
  "details" : [ "axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.", "A flaw was found in axios. A remote attacker could exploit an incomplete depth-limit bypass when the component serializes objects with specific top-level keys. By manipulating object keys and nested values during form or parameter serialization, an attacker can trigger a processing error. This can lead to a denial of service, making the affected request path unavailable to legitimate users." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.13",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60390",
    "cpe" : "cpe:/a:redhat:acm:2.13::el9",
    "package" : "rhacm2/console-rhel9:1787339249",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2.14",
    "release_date" : "2026-08-26T00:00:00Z",
    "advisory" : "RHSA-2026:60388",
    "cpe" : "cpe:/a:redhat:acm:2.14::el9",
    "package" : "rhacm2/console-rhel9:1787339248",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.10",
    "release_date" : "2026-09-15T00:00:00Z",
    "advisory" : "RHSA-2026:67711",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.10::el8",
    "package" : "advanced-cluster-security/rhacs-main-rhel8:1789411269",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security for Kubernetes 4.11",
    "release_date" : "2026-09-15T00:00:00Z",
    "advisory" : "RHSA-2026:67714",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4.11::el9",
    "package" : "advanced-cluster-security/rhacs-main-rhel9:1789411320",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2.1",
    "release_date" : "2026-09-08T00:00:00Z",
    "advisory" : "RHSA-2026:65118",
    "cpe" : "cpe:/a:redhat:ansible_portal:2.1",
    "package" : "ansible-automation-platform/automation-portal:1788775748",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-28T00:00:00Z",
    "advisory" : "RHSA-2026:47619",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "grafana12-4-main-12.4.6-0.2.hum1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-29T00:00:00Z",
    "advisory" : "RHSA-2026:48241",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "grafana13-1-main-13.1.1-0.3.hum1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-30T00:00:00Z",
    "advisory" : "RHSA-2026:48758",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "jaeger-main-2.20.0-0.8.hum1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Migration Toolkit 1.8",
    "release_date" : "2026-09-17T00:00:00Z",
    "advisory" : "RHSA-2026:68681",
    "cpe" : "cpe:/a:redhat:rhmt:1.8::el8",
    "package" : "rhmtc/openshift-migration-ui-rhel8:1789546373",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces 3.30",
    "release_date" : "2026-09-17T00:00:00Z",
    "advisory" : "RHSA-2026:68754",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3.30::el9",
    "package" : "devspaces/dashboard-rhel9:1789162884",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 3.3",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59566",
    "cpe" : "cpe:/a:redhat:service_mesh:3.3::el9",
    "package" : "openshift-service-mesh/kiali-ossmc-rhel9:1787076322",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 3.3",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59566",
    "cpe" : "cpe:/a:redhat:service_mesh:3.3::el9",
    "package" : "openshift-service-mesh/kiali-rhel9:1787077108",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 3.4",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59583",
    "cpe" : "cpe:/a:redhat:service_mesh:3.4::el9",
    "package" : "openshift-service-mesh/kiali-ossmc-rhel9:1787166293",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Service Mesh 3.4",
    "release_date" : "2026-08-25T00:00:00Z",
    "advisory" : "RHSA-2026:59583",
    "cpe" : "cpe:/a:redhat:service_mesh:3.4::el9",
    "package" : "openshift-service-mesh/kiali-rhel9:1787165683",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Quay 3.10",
    "release_date" : "2026-09-09T00:00:00Z",
    "advisory" : "RHSA-2026:66084",
    "cpe" : "cpe:/a:redhat:quay:3.10::el8",
    "package" : "quay/quay-rhel8:1788561841",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Quay 3.12",
    "release_date" : "2026-09-10T00:00:00Z",
    "advisory" : "RHSA-2026:66523",
    "cpe" : "cpe:/a:redhat:quay:3.12::el8",
    "package" : "quay/quay-rhel8:1788594376",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Quay 3.14",
    "release_date" : "2026-09-22T00:00:00Z",
    "advisory" : "RHSA-2026:70267",
    "cpe" : "cpe:/a:redhat:quay:3.14::el8",
    "package" : "quay/quay-rhel8:1788593843",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Quay 3.16",
    "release_date" : "2026-09-21T00:00:00Z",
    "advisory" : "RHSA-2026:69255",
    "cpe" : "cpe:/a:redhat:quay:3.16::el9",
    "package" : "quay/quay-rhel9:1789563753",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Quay 3.9",
    "release_date" : "2026-09-08T00:00:00Z",
    "advisory" : "RHSA-2026:65514",
    "cpe" : "cpe:/a:redhat:quay:3.9::el8",
    "package" : "quay/quay-rhel8:1788595574",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Satellite 6.18",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63373",
    "cpe" : "cpe:/a:redhat:satellite:6.18::el9",
    "package" : "satellite/iop-host-inventory-frontend-rhel9:1788322243",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Satellite 6.18",
    "release_date" : "2026-09-17T00:00:00Z",
    "advisory" : "RHSA-2026:68765",
    "cpe" : "cpe:/a:redhat:satellite:6.18::el9",
    "package" : "satellite/iop-vulnerability-frontend-rhel9:1789660969",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Satellite 6.19",
    "release_date" : "2026-09-03T00:00:00Z",
    "advisory" : "RHSA-2026:63355",
    "cpe" : "cpe:/a:redhat:satellite:6.19::el9",
    "package" : "satellite/iop-host-inventory-frontend-rhel9:1788260941",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Satellite 6.19",
    "release_date" : "2026-09-17T00:00:00Z",
    "advisory" : "RHSA-2026:68748",
    "cpe" : "cpe:/a:redhat:satellite:6.19::el9",
    "package" : "satellite/iop-advisor-frontend-rhel9:1789659565",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Satellite 6.19",
    "release_date" : "2026-09-17T00:00:00Z",
    "advisory" : "RHSA-2026:68755",
    "cpe" : "cpe:/a:redhat:satellite:6.19::el9",
    "package" : "satellite/iop-vulnerability-frontend-rhel9:1789660983",
    "impact" : "important"
  } ],
  "package_state" : [ {
    "product_name" : "Migration Toolkit for Applications 8",
    "fix_state" : "Affected",
    "package_name" : "mta/mta-ui-rhel9",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:8",
    "impact" : "important"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Affected",
    "package_name" : "multicluster-engine/console-mce-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine",
    "impact" : "important"
  }, {
    "product_name" : "Network Observability Operator",
    "fix_state" : "Not affected",
    "package_name" : "network-observability/network-observability-console-plugin-pf4-rhel9",
    "cpe" : "cpe:/a:redhat:network_observ_optr:1",
    "impact" : "important"
  }, {
    "product_name" : "Network Observability Operator",
    "fix_state" : "Not affected",
    "package_name" : "network-observability/network-observability-console-plugin-pf5-rhel9",
    "cpe" : "cpe:/a:redhat:network_observ_optr:1",
    "impact" : "important"
  }, {
    "product_name" : "Network Observability Operator",
    "fix_state" : "Not affected",
    "package_name" : "network-observability/network-observability-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:network_observ_optr:1",
    "impact" : "important"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Will not fix",
    "package_name" : "openshift-pipelines/pipelines-hub-ui-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Ansible Automation Platform 2",
    "fix_state" : "Will not fix",
    "package_name" : "automation-gateway",
    "cpe" : "cpe:/a:redhat:ansible_automation_platform:2",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat build of Apicurio Registry 3",
    "fix_state" : "Not affected",
    "package_name" : "apicurio/apicurio-registry-ui-rhel8",
    "cpe" : "cpe:/a:redhat:apicurio_registry:3",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat build of Apicurio Registry 3",
    "fix_state" : "Affected",
    "package_name" : "apicurio/apicurio-registry-ui-rhel9",
    "cpe" : "cpe:/a:redhat:apicurio_registry:3",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-dashboard-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Not affected",
    "package_name" : "rhoai/odh-mlflow-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-automl-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-autorag-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-eval-hub-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-gen-ai-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-maas-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-mlflow-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Affected",
    "package_name" : "rhoai/odh-mod-arch-model-registry-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift4/ose-console",
    "cpe" : "cpe:/a:redhat:openshift:4",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift4/ose-console-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Affected",
    "package_name" : "devspaces/code-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat OpenShift Virtualization 4",
    "fix_state" : "Not affected",
    "package_name" : "container-native-virtualization/kubevirt-console-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:container_native_virtualization:4",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Trusted Profile Analyzer",
    "fix_state" : "Affected",
    "package_name" : "rhtpa/rhtpa-trustification-service-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_profile_analyzer:2",
    "impact" : "important"
  }, {
    "product_name" : "Red Hat Trusted Profile Analyzer",
    "fix_state" : "Affected",
    "package_name" : "rhtpa/rhtpa-rhel10",
    "cpe" : "cpe:/a:redhat:trusted_profile_analyzer:3",
    "impact" : "important"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-67321\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-67321\nhttps://github.com/axios/axios/security/advisories/GHSA-hcpx-6fm6-wx23\nhttps://www.vulncheck.com/advisories/axios-before-denial-of-service-via-maxdepth-bypass" ],
  "name" : "CVE-2026-67321",
  "csaw" : false
}