REDHAT-BUG-2461630: High severity npm/axios vulnerability
Published Apr 24, 2026
·Updated
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.
Affected Software
1 affected component
npm/axios<1.15.1, <0.31.1
Event History
Apr 24, 2026
Data Sourced
via Red Hat·07:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2461630?
The severity of REDHAT-BUG-2461630 is high with a rating of 7.
2
How do I fix REDHAT-BUG-2461630?
To fix REDHAT-BUG-2461630, update Axios to version 1.15.1 or 0.31.1 or later.
3
What is the risk associated with REDHAT-BUG-2461630?
REDHAT-BUG-2461630 has a risk score of 33, indicating a significant potential impact.
4
What problem does REDHAT-BUG-2461630 cause?
REDHAT-BUG-2461630 causes a RangeError that crashes the Node.js process when deeply nested values are passed as request data.
5
Which software is affected by REDHAT-BUG-2461630?
The affected software is npm/axios versions prior to 1.15.1 and 0.31.1.