Uncontrolled Recursion Affecting awx package, versions <24.6.1-r45


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.53% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-AWX-19655460
  • published9 Sept 2026
  • disclosed1 Aug 2026

Introduced: 1 Aug 2026

CVE-2026-67321  (opens in a new tab)
CWE-674  (opens in a new tab)

How to fix?

Upgrade Chainguard awx to version 24.6.1-r45 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream awx package and not the awx package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization can trigger a RangeError from JSON.stringify, causing denial of service in the affected request path.

CVSS Base Scores

version 3.1