Uncontrolled Recursion in axios - CVE-2026-42039
Published: April 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in toFormData in lib/helpers/toFormData.js when processing deeply nested request data or params objects. A remote attacker can send a deeply nested object to cause a denial of service.
The issue can be reached in server-side code that forwards client-controlled objects into axios request data or params, and may terminate the running request handler or process with a RangeError.
Affected software
IBM Cloud Pak System
IBM MQ Operator
IBM Decision Optimization for Cloud Pak for Data
IBM supplied MQ Advanced container images
JBoss Data Grid
How to mitigate CVE-2026-42039
IBM Cloud Pak System - update to 2.3.5.1
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
IBM Decision Optimization for Cloud Pak for Data - update to 5.3.1 patch 6
JBoss Data Grid - update to 8.6.1