Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

axios — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting axios. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Axios is a widely adopted HTTP client for JavaScript environments, primarily utilized in browser and Node.js applications to simplify asynchronous data fetching. Despite its popularity, the library has faced 21 recorded Common Vulnerabilities and Exposures (CVEs), predominantly stemming from improper input validation and prototype pollution issues. These flaws often enable remote code execution or cross-site scripting attacks when user-controlled data is passed directly into configuration objects without sanitization. Notably, several vulnerabilities allowed attackers to bypass security controls by manipulating internal headers or request parameters. While Axios itself does not store data, its widespread integration into frontend frameworks makes it a frequent target for supply chain attacks. Developers must ensure strict input validation and keep dependencies updated to mitigate risks associated with these historical security gaps, particularly in applications handling sensitive user information.

Found 1 results / 41Clear Filters
Top products by axios: axios axios/axios
HighUSN-8638-12026-08-13
USN-8638-1: Axios vulnerabilities | Ubuntu security notices | Ubuntu
High2026-08-01
HTTP/2 streamed uploads bypass `maxBodyLength` · Advisory · axios/axios · GitHub
High2026-08-01
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning · Advisory · axios/axios · GitHub
Medium2026-08-01
Deep formToJSON Key Recursion Can Cause Denial of Service · Advisory · axios/axios · GitHub
High2026-08-01
Prototype pollution gadgets can alter axios request construction · Advisory · axios/axios · GitHub
Medium2026-08-01
Excessive recursion in formDataToJSON can cause denial of service · Advisory · axios/axios · GitHub
Medium2026-08-01
Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` · Advisory · axios/axios · GitHub
HighGHSA-x8qg-cv0w-x6jj2026-08-01
Prototype pollution auth subfields can inject Basic auth · Advisory · axios/axios · GitHub
High2026-08-01
NO_PROXY bypass for 0.0.0.0 local addresses in axios · Advisory · axios/axios · GitHub
Medium2026-08-01
Nested axios option objects can consume polluted prototype values · Advisory · axios/axios · GitHub
Medium2026-08-01
Axios form serializer maxDepth bypass via {} metatoken · Advisory · axios/axios · GitHub
High2026-05-08
fix: more header pollutions (#10779) · axios/axios@4791514 · GitHub
HighGHSA-q8qp-cvcw-x6jg2026-05-08
fix: more header pollutions by jasonsaayman · Pull Request #10779 · axios/axios · GitHub
High2026-05-08
Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking · Advisory · axio
High2026-05-08
Release v1.15.2 · axios/axios · GitHub
High2026-04-25
Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy · Advisory · axios/axios · GitHu
HighCVE-2025-627182026-04-25
[Patch Bypass] Incomplete Fix for GHSA-3p68-rc4w-qgx5 (CVE-2025-62718) — NO_PROXY Protection Bypassed via RFC 1122 Loopb
Critical2026-04-25
Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` · Advisory · axios/axios · GitHub
Medium2026-04-25
CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream · Advisory · axios/axios · GitH
MediumCVE-2026-42422026-04-25
XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion · Advisory · axios/ax

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with axios. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.