axios vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-GCFJ-64VW-6MP9Highaxios: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloningGHSA-HCPX-6FM6-WX23Mediumaxios: Axios form serializer maxDepth bypass via {} metatokenGHSA-7Q8Q-RJ6J-MHJQMediumaxios: Axios: Nested axios option objects can consume polluted prototype valuesGHSA-MWF2-3PR3-8698Mediumaxios: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`GHSA-JQH4-M9W3-8HP9Mediumaxios: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`GHSA-MMX7-HFXF-JPPXMediumaxios: Axios: Prototype pollution gadgets can alter axios request constructionGHSA-F4GW-2P7V-4548Mediumaxios: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axiosGHSA-42H9-826W-CGV3Mediumaxios: Axios: Excessive recursion in formDataToJSON can cause denial of serviceCVE-2026-67314Mediumaxios: Axios: Prototype pollution auth subfields can inject Basic authGHSA-PMV8-RQ9R-6J72Mediumaxios: Axios: Deep formToJSON Key Recursion Can Cause Denial of ServiceCVE-2026-44496Highaxios: Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectionCVE-2026-44488Highaxios: Allocation of Resources Without Limits or Throttling in AxiosCVE-2026-44487Highaxios: Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterCVE-2026-44486Highaxios: Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionCVE-2026-44495Highaxios: axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeCVE-2026-44494Highaxios: axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`CVE-2026-44492Highaxios: axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)CVE-2026-44490Mediumaxios: axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsCVE-2026-44489Lowaxios: Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype FixCVE-2026-42037Mediumaxios: Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamCVE-2026-42038Mediumaxios: Axios: no_proxy bypass via IP alias allows SSRFCVE-2026-42039Mediumaxios: Axios: unbounded recursion in toFormData causes DoS via deeply nested request dataCVE-2026-42034Mediumaxios: Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0CVE-2026-42036Mediumaxios: Axios: HTTP adapter streamed responses bypass maxContentLengthCVE-2026-42033Highaxios: Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

Stop the waste.
Protect your environment with Kodem.