axios
axios
| Version / range | Status | Type |
|---|---|---|
| >= 1.16.1, < 1.20.0 | affected | — |
Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash characters and no comma. the JavaScript regular-expression engine explores many separator placements before rejecting the URL. Synchronous excessive backtracking can block the Node.js event loop and cause denial of service. The affected identifiers are fromDataURI, DATA_URL_PATTERN, data:. This issue is fixed in version 1.20.0.
Risk score
8.2
CVSS 4.0
axios
| Version / range | Status | Type |
|---|---|---|
| >= 1.16.1, < 1.20.0 | affected | — |
8.2
CVSS 4.0