Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

Denial of Service in axios

GHSA-42xw-2xvc-qx8m · CVE-2019-10742

Published · Modified

Description

Versions of axios prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the maxContentLength property, the package prints an error but does not stop the request. This may cause high CPU usage and lead to Denial of Service.

Recommendation

Upgrade to 0.18.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes