Description
For stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits.
Recommendation
Update the axios package to the latest compatible version. Followings are version details:
Affected version(s): **<= 0.31.0 >= 1.0.0, < 1.15.1** Patched version(s): **0.31.1 1.15.1**
References
Could your website be exposed too?
SmartScanner can check your website for Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0 and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Axios: HTTP adapter streamed responses bypass maxContentLength - CVE-2026-42036
- Axios: HTTP/2 streamed uploads bypass `maxBodyLength` - Vulnerability
- Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` - Vulnerability
- Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking - CVE-2026-42264


