CVE-2026-42037 | Axios up to 1.15.0 Content-Type Header formDataToStream.js crlf injection (GHSA-445q-vr5w-6q77)
A vulnerability was found in Axios up to 1.15.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality in the library lib/helpers/formDataToStream.js of the component Content-Type Header Handler. The manipulation leads to crlf injection.
This vulnerability is listed as CVE-2026-42037. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.