vulns.co
/
GKData.io MCP

Axios · 2 min read

Axios: enforce upload budgets across transport implementations

CVE-2026-68948 documents a transport-contract mismatch: an application configured an outbound body limit, but the HTTP/2 stream path delegated to a transport that did not enforce it. The maintainer-published report describes local observation of transmission beyond that budget. Bandwidth, quota and availability consequences are application-dependent; the advisory excludes code execution, credential disclosure and destination control.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The maintainer identifies 1.18.0 as patched. Review byte-budget enforcement as an invariant shared by transport adapters. The merged remediation describes consistent upload/content limits and regression coverage. Editorial lesson: enforce limits during consumption of unknown-length input and ensure failure cancels downstream work; configuration metadata alone is not enforcement.

Before reading

  • HTTP transport adapters and streamed request bodies
  • Resource budgets and failure propagation

Context and limits

  • Exposure requires untrusted stream influence, the Node HTTP adapter using HTTP/2, and a finite configured body limit. Buffered bodies and browser adapters are excluded from this advisory.
  • The advisory credits asadeddin as reporter; jasonsaayman is the publishing maintainer, not an inferred discoverer.
  • The advisory retains old prose saying no fixed release exists, while its patched-version metadata identifies 1.18.0 and the dated release corroborates stream-limit hardening. These distinct source states are preserved.
  • No production incident, measured billing loss or bounty amount was established. Learning prerequisites and generalized design advice are editorial.
  • The cited software release is dated 2026-06-13; it is distinct from the advisory publication and is not a claim about the latest available release.
  • The advisory lists affected versions as >=1.13.0 and patched versions as >=1.18.0; its affected-range metadata lacks an upper bound. These overlapping published fields do not establish that patched releases remain vulnerable.

Sources and provenance

  1. HTTP/2 streamed uploads bypass maxBodyLength Axios · reviewed 2026-10-03
  2. Axios v1.18.0 release Axios · reviewed 2026-10-03
  3. Merged request hardening and stream-limit changes Axios · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software