Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Security Intel Hub 23+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
High
Axios Prototype Pollution Leading to Request Hijacking (GHSA-q8qp-cvcw-x6jg)
GHSA-q8qp-cvcw-x6jg · github.com · 2026-05-08
Axios HTTP client library
Read more
Medium
HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0 · Advisory · axios/axios · GitHub
CVE-2024-20534 · github.com · 2026-04-25
axios <= 1.15.0 · axios <= 0.31.0
Read more
Medium
no_proxy bypass via IP alias allows SSRF · Advisory · axios/axios · GitHub
CVE-2026-42538 · github.com · 2026-04-25
axios <=1.15.0 · axios <0.31.0
Read more
High
Header Injection via Prototype Pollution · Advisory · axios/axios · GitHub
CVE-2024-2035 · github.com · 2026-04-25
axios <=1.15.0 · axios <=0.31.0
Read more
Unknown
Axios Fix: Sanitization of Invalid Characters in HTTP Request Headers
github.com · 2026-04-18

### Vulnerability Overview This vulnerability involves issues with handling invalid characters in HTTP requests. Specifically, when an invalid character appears in the request header, it may lead to s…

Read more
High
Axios CRLF Header Injection Leading to Cloud Metadata Exfiltration Fix
github.com · 2026-04-11

### Vulnerability Overview **Title**: `fix: unrestricted cloud metadata exfiltration via header injection chain #10660` This is a security fix for the Axios library aimed at preventing attackers from …

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.