High [CVE-2026-67312] Denial of Service via uncontrolled recursion in form data processing
This high-severity Red Hat Linux advisory covers CVE-2026-67312 affecting Red Hat Developer Hub 1.10, Red Hat Developer Hub 1.9, Red Hat Hardened Images.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json).
When an application passes attacker-controlled FormData field names, a field name with thousands of nested bracket-delimited segments causes unbounded recursion in buildPath(), exhausting the JavaScript call stack (RangeError: Maximum call stack size exceeded) and causing denial of service for that request, or process termination in applications without appropriate error handling.
A flaw was found in axios, a popular JavaScript library. An attacker can exploit this vulnerability by providing malicious form data containing deeply nested field names.
This input triggers uncontrolled recursion within the formDataToJSON function, which is responsible for processing form data. This vulnerability affects applications that pass attacker-controlled FormData field names to axios' FormData-to-JSON conversion.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-674.
Affected products named by the advisory: Red Hat Developer Hub 1.10; Red Hat Developer Hub 1.9; Red Hat Hardened Images; Red Hat OpenShift Dev Spaces 3.30; and 4 more.
- < 0.28.0
- < 0.33.0
- < 1.0.0
- < 1.18.0
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
- rhdh/rhdh-hub-rhel9:1788286049
- rhdh/rhdh-hub-rhel9:1789554285
- grafana12-4-main-12.4.6-0.2.hum1
- grafana13-1-main-13.1.1-0.3.hum1
- jaeger-main-2.20.0-0.8.hum1
- devspaces/dashboard-rhel9:1789162884
- RHSA-2026:62851
- RHSA-2026:69248
- RHSA-2026:47619
- RHSA-2026:48241
- RHSA-2026:48758
- RHSA-2026:68754
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
Mitigation checklist
- Upgrade to axios >= 1.18.0 (1.x) or >= 0.33.0 (0.x), which add recursion depth guards to formDataToJSON. If an immediate upgrade is not possible, validate and limit the nesting depth of FormData field names before passing them to axios.formToJSON() or before sending FormData through axios with Content-Type: application/json, and ensure error handling is in place to catch RangeError exceptions from this code path.
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.