LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-42034

CVE-2026-42034 - Vulnerability Analysis

MediumCVSS: 5.3

Last Updated: April 27, 2026

Axios - Misconfiguration

Published: April 24, 2026Updated: April 27, 2026PoC AvailableRemote Exploitable

Overview

Axios < 1.15.1 and < 0.31.1 contains a bypass of maxBodyLength limit caused by maxRedirects set to 0 in native http/https transport, letting attackers send oversized streamed uploads, exploit requires crafted request.

Severity & Score

Severity: Medium
CVSS Score: 5.3

Impact

Attackers can send oversized uploads bypassing body size limits, potentially causing resource exhaustion or denial of service.

Mitigation

Update to version 1.15.1 or 0.31.1 or later.

Details

CVE ID
CVE-2026-42034
Severity
Medium
CVSS Score
5.3
Type
misconfiguration
Status
confirmed

CWE

  • CWE-770

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L