Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Security Vulnerability: Axios DoS in authorizenet dependency #103

Copy link
Copy link
@TylerBurr

Description

@TylerBurr
Issue body actions

Summary
The authorizenet package (v1.0.10) contains a transitive dependency on a vulnerable version of axios (< 1.12.0) that is susceptible to a Denial of Service attack.

Vulnerability Details
CVE ID: CVE-2025-27152
GHSA ID: GHSA-4hjh-wcwx-xvwj
Severity: High
Discovery Date: July 12, 2025
Vulnerability: Axios is vulnerable to DoS attack through lack of data size check
Attack Vector: Supplying very large data: URIs causes unbounded memory allocation and potential process crash

Reactions are currently unavailable

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      Morty Proxy This is a proxified and sanitized view of the page, visit original site.