CVE-2026-67321
axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing obje
CVSS
7.5
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 1 ago 2026 · Última mod.: 1 sept 2026 · CWE-674
0.3%EPSS · 30 días0.4%
2026-08-202026-09-17
axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-19248—34.8%
——10QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.2dCVE-2026-123587.5 ALT32.4%
——10IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.2dCVE-2026-919686.5 MED30.4%
——9vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to exhaust memory and terminate the API process.2dCVE-2026-537527.5 ALT37.5%
——11docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A well-formed DOCX containing mutually based styles causes unbounded recursion in PropertyResolver.fillPPrStack and related effective-style resolution paths, resulting in StackOverflowError. Server-side conversion and table-of-contents processing of an untrusted document can terminate a worker thread, degrade a thread pool, or deny service, although isolation in disposable workers or safe containment of StackOverflowError can reduce the practical effect. The fix adds cyclic-style tracking and CyclicStylesException handling. This issue is fixed in version 11.5.14.2dCVE-2026-904725.3 MED26.5%
——8msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.4dCVE-2026-887635.9 MED16.6%
——5A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.4d