Axios 1.15.1/0.31.1 CRASH via toFormData deep nesting
CVE-2026-42039 Published on April 24, 2026
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.
Vulnerability Analysis
CVE-2026-42039 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Types
What is a Stack Exhaustion Vulnerability?
The product does not properly control the amount of recursion which takes place, consuming excessive resources, such as allocated memory or the program stack.
CVE-2026-42039 has been classified to as a Stack Exhaustion vulnerability or weakness.
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2026-42039
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42039 are published in these products:
Affected Versions
axios:- Version >= 1.0.0, < 1.15.1 is affected.
- Version < 0.31.1 is affected.
- Version 1780917531 and below * is unaffected.
- Version 1780910888 and below * is unaffected.
- Version 1778511348 and below * is unaffected.
- Version 1778383863 and below * is unaffected.
- Version 1778532610 and below * is unaffected.
- Version 1778510461 and below * is unaffected.
- Version 1780920979 and below * is unaffected.
- Version 1783451729 and below * is unaffected.
- Version 1780876734 and below * is unaffected.
- Version 1780600823 and below * is unaffected.
- Version 1779371594 and below * is unaffected.
- Version 1779293013 and below * is unaffected.
- Version 1779841586 and below * is unaffected.
- Version 1781187342 and below * is unaffected.
- Version 1782761244 and below * is unaffected.
- Version 1778156756 and below * is unaffected.
- Version 1780590717 and below * is unaffected.
- Version 1780467029 and below * is unaffected.
- Version 1780467147 and below * is unaffected.
- Version 1778645099 and below * is unaffected.
- Version 1778539338 and below * is unaffected.
- Version 1779814592 and below * is unaffected.
- Version 1779341289 and below * is unaffected.
- Version 1778191473 and below * is unaffected.
- Version 1778191378 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778164208 and below * is unaffected.
- Version 1778163935 and below * is unaffected.
- Version 1778164042 and below * is unaffected.
- Version 1778163792 and below * is unaffected.
- Version 1778163909 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778163986 and below * is unaffected.
- Version 1779822261 and below * is unaffected.
- Version 1779811412 and below * is unaffected.
- Version 1779689392 and below * is unaffected.
- Version 1780891395 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1779922205 and below * is unaffected.
- Version 1779811473 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
- Version 1781032495 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.