Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-67312] Denial of Service via uncontrolled recursion in form data processing

This high-severity Red Hat Linux advisory covers CVE-2026-67312 affecting Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9, Red Hat Hardened Images.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-67312 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json).

When an application passes attacker-controlled FormData field names, a field name with thousands of nested bracket-delimited segments causes unbounded recursion in buildPath(), exhausting the JavaScript call stack (RangeError: Maximum call stack size exceeded) and causing denial of service for that request, or process termination in applications without appropriate error handling.

A flaw was found in axios, a popular JavaScript library. An attacker can exploit this vulnerability by providing malicious form data containing deeply nested field names.

This input triggers uncontrolled recursion within the formDataToJSON function, which is responsible for processing form data. This vulnerability affects applications that pass attacker-controlled FormData field names to axios' FormData-to-JSON conversion.

Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-674.

Affected products named by the advisory: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Hardened Images; Red Hat OpenShift Dev Spaces 3.30; and 4 more.

Affected versions
  • < 0.28.0
  • < 0.33.0
  • < 1.0.0
  • < 1.18.0

Official advisory · high-confidence parse· fetched 2 days ago·verify at source

Fixed versions
  • rhdh/rhdh-hub-rhel9:1788286049
  • rhdh/rhdh-hub-rhel9:1789554285
  • grafana12-4-main-12.4.6-0.2.hum1
  • grafana13-1-main-13.1.1-0.3.hum1
  • jaeger-main-2.20.0-0.8.hum1
  • devspaces/dashboard-rhel9:1789162884
  • RHSA-2026:62851
  • RHSA-2026:69248
  • RHSA-2026:47619
  • RHSA-2026:48241
  • RHSA-2026:48758
  • RHSA-2026:68754

Official advisory · high-confidence parse· fetched 2 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to axios >= 1.18.0 (1.x) or >= 0.33.0 (0.x), which add recursion depth guards to formDataToJSON. If an immediate upgrade is not possible, validate and limit the nesting depth of FormData field names before passing them to axios.formToJSON() or before sending FormData through axios with Content-Type: application/json, and ensure error handling is in place to catch RangeError exceptions from this code path.

Official advisory · high-confidence parse· fetched 2 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.