PT-2025-37272 · Openjs Foundation+1 · Axios+1

Ameerassadi

·

Published

2025-09-11

·

Updated

2026-05-08

·

CVE-2025-58754

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Axios versions prior to 1.11.0
Description Axios, a promise-based HTTP client for browsers and Node.js, is susceptible to a denial-of-service (DoS) attack when running on Node.js and processing URLs with the data: scheme. The Node http adapter decodes the entire payload from the data: URI into memory without size limitations, ignoring maxContentLength and maxBodyLength configurations. This allows an attacker to supply a large data: URI, causing unbounded memory allocation and potentially crashing the process, even when responseType is set to 'stream'. Approximately 2.2 million instances are potentially vulnerable.
Recommendations Update to Axios version 1.11.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-58754
GHSA-4HJH-WCWX-XVWJ
RHSA-2025:23069

Affected Products

Axios
Debian