Skip to main content
Version: v1.3.x

CVE-2026-67313

CVE Details

Visit the official vulnerability details page for CVE-2026-67313 to learn more.

Initial Publication

08/01/2026

Last Update

09/01/2026

Third Party Dependency

axios

NIST CVE Summary

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segments. Attackers can supply FormData with field names containing thousands of nested brackets to exhaust the JavaScript call stack and trigger RangeError, causing request failure or process termination in applications that do not handle the exception.

CVE Severity

7.5

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.3.1⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.