axios
48 known vulnerabilities in axios, 3 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-101909 CVSS 8.3 high Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes…
- CVE-2026-101908 CVSS 6.9 medium Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with…
- CVE-2026-101907 CVSS 7.0 high Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0…
- CVE-2026-101906 CVSS 8.2 high Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic…
- CVE-2026-101905 CVSS 7.6 high Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js…
- CVE-2026-101904 CVSS 6.9 medium Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes…
- CVE-2026-101903 CVSS 8.2 high Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash…
- CVE-2026-101902 CVSS 6.9 medium Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests…
- CVE-2026-101901 CVSS 8.2 high Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error…
- CVE-2026-101900 CVSS 6.9 medium Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited…
- CVE-2026-101898 CVSS 7.0 high Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not…
- CVE-2026-67321 CVSS 6.9 medium axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing…
- CVE-2026-67320 CVSS 8.3 high axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request…
- CVE-2026-67319 CVSS 6.3 medium axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript…
- CVE-2026-67318 CVSS 6.3 medium axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests…
- CVE-2026-67317 CVSS 6.3 medium axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when…
- CVE-2026-67316 CVSS 6.3 medium axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been…
- CVE-2026-67315 CVSS 6.9 medium axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js…
- CVE-2026-67314 CVSS 6.3 medium axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js…
- CVE-2026-67313 CVSS 6.3 medium axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested…
- CVE-2026-67312 CVSS 6.3 medium axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as…
- CVE-2026-44496 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the…
- CVE-2026-44495 CVSS 7.7 high Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains…
- CVE-2026-44494 CVSS 8.7 high Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a…
- CVE-2026-44492 CVSS 8.6 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6…
- CVE-2026-44490 CVSS 8.2 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side…
- CVE-2026-44488 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request…
- CVE-2026-44487 CVSS 8.2 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a…
- CVE-2026-44486 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy…
- CVE-2026-42264 CVSS 9.1 critical Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties…