axios is vulnerable to Uncontrolled Resource Consumption
53
Medium Risk
The fetch-backed request path resolves the same size guard options as the HTTP adapter but previously skipped enforcing them, so responses and bodies could grow without the limits callers configured. The implementation now rejects oversized declared lengths, oversized outbound bodies when length is known, and large data URLs before decoding materializes them. That restores the intended backpressure boundary for deployments that chose the fetch adapter for network I/O.
You are affected if you are using a version that falls within the vulnerable range.
axios is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.15.2.
Upgrade the axios library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant