Lucene search

K
osvGoogleOSV:GHSA-42XW-2XVC-QX8M
HistoryMay 29, 2019 - 6:04 p.m.

Denial of Service in axios

2019-05-2918:04:45
Google
osv.dev
13

EPSS

0.003

Percentile

71.1%

Versions of axios prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the maxContentLength property, the package prints an error but does not stop the request. This may cause high CPU usage and lead to Denial of Service.

Recommendation

Upgrade to 0.18.1 or later.