VulnSea

axios vulnerabilities

CVEs whose affected-version data names the axios package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

28 CVEsRSS

GHSA-3mcp-22mf-vrw3Medium· 7.5
1mo ago

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Duplicate Advisory: Axios form serializer maxDepth bypass via {} metatoken

Sunlitaxios · axiosvia GHSA
CVE-2026-67321Medium· 7.5
1mo ago

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'

axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serializati…

Sunlitaxios · axiosEPSS 0.36%via NVD
GHSA-f4gw-2p7v-4548Medium
2mo ago

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

Sunlitaxios · axiosvia GHSA
GHSA-mmx7-hfxf-jppxMedium
2mo ago

Axios: Prototype pollution gadgets can alter axios request construction

Axios: Prototype pollution gadgets can alter axios request construction

Sunlitaxios · axiosvia GHSA
GHSA-jqh4-m9w3-8hp9Medium
2mo ago

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

Sunlitaxios · axiosvia GHSA
GHSA-mwf2-3pr3-8698Medium
2mo ago

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

Sunlitaxios · axiosvia GHSA
GHSA-7q8q-rj6j-mhjqMedium
2mo ago

Axios: Nested axios option objects can consume polluted prototype values

Axios: Nested axios option objects can consume polluted prototype values

Sunlitaxios · axiosvia GHSA
GHSA-hcpx-6fm6-wx23Medium
2mo ago

Axios form serializer maxDepth bypass via {} metatoken

Axios form serializer maxDepth bypass via {} metatoken

Sunlitaxios · axiosvia GHSA
GHSA-gcfj-64vw-6mp9High
2mo ago

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

Twilightaxios · axiosvia GHSA
GHSA-pmv8-rq9r-6j72Medium
2mo ago

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

Sunlitaxios · axiosvia GHSA
GHSA-xj6q-8x83-jv6gMedium
2mo ago

Axios: Prototype pollution auth subfields can inject Basic auth

Axios: Prototype pollution auth subfields can inject Basic auth

Sunlitaxios · axiosvia GHSA
GHSA-42h9-826w-cgv3Medium
2mo ago

Axios: Excessive recursion in formDataToJSON can cause denial of service

Axios: Excessive recursion in formDataToJSON can cause denial of service

Sunlitaxios · axiosvia GHSA
CVE-2026-44496High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metac…

Midnightaxios · axiosEPSS 0.69%via NVD
CVE-2026-44488High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected …

Midnightaxios · axiosEPSS 0.67%via NVD
CVE-2026-44486High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticat…

Midnightaxios · axiosEPSS 0.68%via NVD
CVE-2026-44495High· 7.0PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…

Midnightaxios · axiosEPSS 0.85%via NVD
CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

Midnightaxios · axiosEPSS 1.0%via NVD
CVE-2026-44492High· 8.6PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL us…

Midnightaxios · axiosEPSS 0.90%via NVD
CVE-2026-44487High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. Th…

Midnightaxios · axiosEPSS 0.69%via NVD
CVE-2026-42264High· 7.4PoC
4mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via d…

Midnightaxios · axiosEPSS 0.71%via NVD
CVE-2026-42044Medium· 6.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…

Twilightaxios · axiosEPSS 0.59%via NVD
CVE-2026-42043High· 7.2PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to complet…

Midnightaxios · axiosEPSS 0.66%via NVD
CVE-2026-42041Medium· 4.8PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HT…

Twilightaxios · axiosEPSS 0.61%via NVD
CVE-2026-42039High· 7.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process wi…

Midnightaxios · axiosEPSS 0.74%via NVD
CVE-2026-42033High· 7.4PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) sil…

Midnightaxios · axiosEPSS 0.84%via NVD
CVE-2026-40175Medium· 4.8PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inje…

Twilightaxios · axiosEPSS 1.9%via NVD
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-25639High· 7.5
7mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own proper…

Twilightaxios · axiosEPSS 2.8%via NVD
axios vulnerabilities (CVEs) · VulnSea