How to use this reference
The maintainer identifies 1.18.0 as patched. Review byte-budget enforcement as an invariant shared by transport adapters. The merged remediation describes consistent upload/content limits and regression coverage. Editorial lesson: enforce limits during consumption of unknown-length input and ensure failure cancels downstream work; configuration metadata alone is not enforcement.
Before reading
- HTTP transport adapters and streamed request bodies
- Resource budgets and failure propagation
Context and limits
- Exposure requires untrusted stream influence, the Node HTTP adapter using HTTP/2, and a finite configured body limit. Buffered bodies and browser adapters are excluded from this advisory.
- The advisory credits asadeddin as reporter; jasonsaayman is the publishing maintainer, not an inferred discoverer.
- The advisory retains old prose saying no fixed release exists, while its patched-version metadata identifies 1.18.0 and the dated release corroborates stream-limit hardening. These distinct source states are preserved.
- No production incident, measured billing loss or bounty amount was established. Learning prerequisites and generalized design advice are editorial.
- The cited software release is dated 2026-06-13; it is distinct from the advisory publication and is not a claim about the latest available release.
- The advisory lists affected versions as >=1.13.0 and patched versions as >=1.18.0; its affected-range metadata lacks an upper bound. These overlapping published fields do not establish that patched releases remain vulnerable.
Sources and provenance
- HTTP/2 streamed uploads bypass maxBodyLength Axios · reviewed 2026-10-03
- Axios v1.18.0 release Axios · reviewed 2026-10-03
- Merged request hardening and stream-limit changes Axios · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.