CVE-2026-42034: Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
For stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42034 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →