Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

axios — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in axios, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known weaknesses associated with the axios HTTP client library, categorized under various security vulnerability types. It collects a comprehensive range of security issues affecting this popular JavaScript library, covering historical data from its initial release through to the most recent updates. By utilizing this resource, users can effectively track vendor advisories related to axios, gain a deeper understanding of specific weakness classes such as server-side request forgery or prototype pollution, and examine the complete vulnerability history of the product. This centralized approach allows developers and security professionals to quickly identify potential risks without needing to scour multiple disparate sources. The information presented is strictly factual, aiming to provide clarity on the security posture of axios over time. Users may find details on how specific exploits were mitigated or remain unresolved, offering valuable context for risk assessment and remediation planning. This tool is designed for those who need precise, actionable data to ensure their applications remain secure against known threats. It serves as a reference point for understanding the evolution of security concerns within the axios ecosystem, helping teams prioritize patching efforts and enhance their overall defense strategy against cyber threats targeting this widely used web library.

Vendor: axios

CVE IDTitleCVSSSeverityPublished
CVE-2026-67321 axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass CWE-674 6.9 Medium2026-08-01
CVE-2026-67318 axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2 CWE-400 6.3 Medium2026-08-01
CVE-2026-67320 axios before 0.33.0 Prototype Pollution via Node HTTP adapter CWE-200 8.3 High2026-08-01
CVE-2026-67312 axios 0.28.0 before 0.33.0 Denial of Service via formToJSON CWE-400 6.3 Medium2026-08-01
CVE-2026-67316 axios before 1.18.0 Prototype Pollution via bodyless methods CWE-1321 6.3 Medium2026-08-01
CVE-2026-67315 axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 CWE-183 6.9 Medium2026-08-01
CVE-2026-67319 axios before 0.33.0 Prototype Pollution via nested option objects CWE-1321 6.3 Medium2026-08-01
CVE-2026-67317 axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream CWE-770 6.3 Medium2026-08-01
CVE-2026-67314 axios before 1.18.0 Prototype Pollution via auth subfields CWE-1321 6.3 Medium2026-08-01
CVE-2026-67313 axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON CWE-400 6.3 Medium2026-08-01
CVE-2026-44486 Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection CWE-200 7.5 High2026-06-11
CVE-2026-44487 Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter CWE-201 8.2 High2026-06-11
CVE-2026-44488 Axios: Allocation of Resources Without Limits or Throttling in axios CWE-770 7.5 High2026-06-11
CVE-2026-44490 Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions CWE-1321 4.8 Medium2026-06-11
CVE-2026-44496 Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection CWE-400 7.5 High2026-06-11
CVE-2026-44495 Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge CWE-94 7.0 High2026-06-11
CVE-2026-44494 Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` CWE-441 8.7 High2026-06-11
CVE-2026-44489 Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix CWE-113 3.7 Low2026-06-11
CVE-2026-44492 Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) CWE-918 8.6 High2026-06-11
CVE-2026-42264 Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking CWE-1321 7.4 High2026-05-08
CVE-2026-42042 Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion CWE-183 5.4 Medium2026-04-24
CVE-2026-42039 Axios: unbounded recursion in toFormData causes DoS via deeply nested request data CWE-674 6.9 Medium2026-04-24
CVE-2026-42036 Axios: HTTP adapter streamed responses bypass maxContentLength CWE-770 5.3 Medium2026-04-24
CVE-2026-42034 Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0 CWE-770 5.3 Medium2026-04-24
CVE-2026-42037 Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream CWE-93 5.3 Medium2026-04-24
CVE-2026-42038 Axios: no_proxy bypass via IP alias allows SSRF CWE-918 6.8 Medium2026-04-24
CVE-2026-42041 Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy CWE-287 4.8 Medium2026-04-24
CVE-2026-42043 Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 CWE-183 7.2 High2026-04-24
CVE-2026-42044 Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` CWE-915 6.5 Medium2026-04-24
CVE-2026-42040 Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams CWE-116 3.7 Low2026-04-24

All 40 known CVE vulnerabilities affecting axios with full Chinese analysis, references, and POCs where available.