Settings

Theme

Taking Down the Internet's Most Popular HTTP Client with a Single JSON Key

striga.ai

10 points by traekfuglene 3 months ago · 2 comments

Reader

traekfugleneOP 3 months ago

We used Striga to discover a high-severity vulnerability in axios, the most downloaded HTTP client in JavaScript. Any Node.js service that forwards user-controlled JSON through axios can be crashed with a single request. CVE-2026-25639. Patched in 1.13.5.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection