High [CVE-2026-67313] Denial of Service via uncontrolled recursion in formDataToJSON
This high-severity Red Hat Linux advisory covers CVE-2026-67313 affecting Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Ansible Automation Platform 2.1.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments.
Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception. A flaw was found in axios.
Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-674.
Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Ansible Automation Platform 2.1; Red Hat Hardened Images; and 22 more.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
- rhacm2/console-rhel9:1787339249
- rhacm2/console-rhel9:1787339248
- ansible-automation-platform/automation-portal:1788775748
- jaeger-main-2.20.0-0.8.hum1
- grafana13-1-main-13.1.1-0.5.hum1
- grafana13-1-main-13.1.1-0.5.2.hum1
- rhoai/odh-dashboard-rhel9:1788312226
- rhoai/odh-mod-arch-model-registry-rhel9:1788312157
- openshift-service-mesh/kiali-ossmc-rhel9:1787077028
- openshift-service-mesh/kiali-rhel9:1787076495
- openshift-service-mesh/kiali-ossmc-rhel9:1787075730
- openshift-service-mesh/kiali-rhel9:1787092198
- openshift-service-mesh/kiali-ossmc-rhel9:1787077188
- openshift-service-mesh/kiali-rhel9:1787092255
- openshift-service-mesh/kiali-ossmc-rhel9:1787076322
- openshift-service-mesh/kiali-rhel9:1787077108
- openshift-service-mesh/kiali-ossmc-rhel9:1787166293
- openshift-service-mesh/kiali-rhel9:1787165683
- quay/quay-rhel8:1788561841
- quay/quay-rhel8:1788595574
- satellite/iop-host-inventory-frontend-rhel9:1788322243
- satellite/iop-host-inventory-frontend-rhel9:1788260941
- RHSA-2026:60390
- RHSA-2026:60388
- RHSA-2026:65118
- RHSA-2026:48758
- RHSA-2026:49714
- RHSA-2026:50826
- RHSA-2026:65126
- RHSA-2026:59548
- RHSA-2026:59561
- RHSA-2026:59554
- RHSA-2026:59566
- RHSA-2026:59583
- RHSA-2026:66084
- RHSA-2026:65514
- RHSA-2026:63373
- RHSA-2026:63355
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Mitigation
Upgrade to a fixed release: rhacm2/console-rhel9:1787339249, rhacm2/console-rhel9:1787339248, ansible-automation-platform/automation-portal:1788775748, jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.5.hum1, grafana13-1-main-13.1.1-0.5.2.hum1. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.