CVE-2025-58754
This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI and cause the process to allocate unbounded memory and crash (DoS), even if the caller requested…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.14%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (`Buffer`/`Blob`) and returns a synthetic 200 response. This path ignores `maxContentLength` / `maxBodyLength` (which only protect HTTP responses), so an attacker can supply a very large `data:` URI and cause the process to allocate unbounded memory and crash (DoS), even if the caller requested `responseType: 'stream'`. Versions 0.30.2 and 1.12.0 contain a patch for the issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- axios/axios
- Source
- security-advisories@github.com
References
- https://github.com/axios/axios/commit/945435fc51467303768202250debb8d4ae892593Patch
- https://github.com/axios/axios/commit/a1b1d3f073a988601583a604f5f9f5d05a3d0b67Patch
- https://github.com/axios/axios/commit/c30252f685e8f4326722de84923fcbc8cf557f06
- https://github.com/axios/axios/pull/7011Issue Tracking, Patch
- https://github.com/axios/axios/pull/7034Issue Tracking
- https://github.com/axios/axios/releases/tag/v0.30.2Release Notes
- https://github.com/axios/axios/releases/tag/v1.12.0Release Notes
- https://github.com/axios/axios/security/advisories/GHSA-4hjh-wcwx-xvwjExploit, Vendor Advisory
- https://github.com/axios/axios/security/advisories/GHSA-4hjh-wcwx-xvwjExploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.