First published: Tue May 07 2019(Updated: )
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Axios Axios node.js | <=0.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10742 is a vulnerability in Axios up to and including version 0.18.0 that allows attackers to cause a denial of service (application crash) by sending content that exceeds the maxContentLength.
CVE-2019-10742 has a severity score of 7.5, which is classified as high.
Axios up to and including version 0.18.0 is affected by CVE-2019-10742.
To fix CVE-2019-10742, upgrade Axios to a version that is above 0.18.0.
You can find more information about CVE-2019-10742 in the references provided: [Link 1](https://app.snyk.io/vuln/SNYK-JS-AXIOS-174505), [Link 2](https://github.com/axios/axios/issues/1098), [Link 3](https://github.com/axios/axios/pull/1485).