Skip to content

Security Vulnerability: Axios DoS in authorizenet dependency #103

@TylerBurr

Description

@TylerBurr

Summary
The authorizenet package (v1.0.10) contains a transitive dependency on a vulnerable version of axios (< 1.12.0) that is susceptible to a Denial of Service attack.

Vulnerability Details
CVE ID: CVE-2025-27152
GHSA ID: GHSA-4hjh-wcwx-xvwj
Severity: High
Discovery Date: July 12, 2025
Vulnerability: Axios is vulnerable to DoS attack through lack of data size check
Attack Vector: Supplying very large data: URIs causes unbounded memory allocation and potential process crash

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions