Taking Down the Internet's Most Popular HTTP Client with a Single JSON Key
1–3 of 3 posts
Re: Taking Down the Internet's Most Popular HTTP Client with a Single JSON Key
#2We used Striga to discover a high-severity vulnerability in axios, the most downloaded HTTP client in JavaScript. Any Node.js service that forwards user-controlled JSON through axios can be crashed with a single request. CVE-2026-25639. Patched in 1.13.5.
Re: Taking Down the Internet's Most Popular HTTP Client with a Single JSON Key
#3[flagged]