Description
Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter.
Recommendation
Update the axios package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.7.0, < 1.16.0
- Patched version(s): 1.16.0
References
Related Issues
- Allocation of Resources Without Limits or Throttling in vriteio/vrite - CVE-2023-5573
- LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning - CVE-2026-45134
- Axios HTTP/2 Session Cleanup State Corruption Vulnerability - CVE-2026-39865
- Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams - CVE-2026-42040
You might also like:
- Tags:
- npm
- axios
Anything's wrong? Let us know Last updated on June 12, 2026


