Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

axios — Vulnerabilities & Security Advisories 40

All 40 CVE vulnerabilities found in axios, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities associated with the axios HTTP client library, categorized under common weakness types such as cross-site scripting and injection flaws. It collects a comprehensive list of disclosed security issues, encompassing high-severity exploits to low-risk configuration weaknesses, covering the historical period from the library’s initial public release through recent updates. Readers can use this resource to track the vendor’s advisory history, understand the specific impact of each vulnerability class on web applications, and investigate the full vulnerability history of the product over time. By reviewing these entries, developers and security analysts can assess the evolution of security practices surrounding axios, identify patterns in reported exploits, and evaluate the current risk posture of their systems. The data is organized to facilitate efficient searching by severity, publication date, and affected versions, enabling informed decision-making regarding patching and mitigation strategies. This compilation serves as a reference point for understanding how widely used libraries like axios have been targeted and addressed by security researchers and the development community. It is intended for use by technical professionals who require accurate, structured information to maintain secure software architectures and comply with organizational security standards.

Vendor: axios

CVE IDTitleCVSSSeverityPublished
CVE-2026-67321 axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass CWE-674 6.9 Medium2026-08-01
CVE-2026-67318 axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2 CWE-400 6.3 Medium2026-08-01
CVE-2026-67320 axios before 0.33.0 Prototype Pollution via Node HTTP adapter CWE-200 8.3 High2026-08-01
CVE-2026-67312 axios 0.28.0 before 0.33.0 Denial of Service via formToJSON CWE-400 6.3 Medium2026-08-01
CVE-2026-67316 axios before 1.18.0 Prototype Pollution via bodyless methods CWE-1321 6.3 Medium2026-08-01
CVE-2026-67315 axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 CWE-183 6.9 Medium2026-08-01
CVE-2026-67319 axios before 0.33.0 Prototype Pollution via nested option objects CWE-1321 6.3 Medium2026-08-01
CVE-2026-67317 axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream CWE-770 6.3 Medium2026-08-01
CVE-2026-67314 axios before 1.18.0 Prototype Pollution via auth subfields CWE-1321 6.3 Medium2026-08-01
CVE-2026-67313 axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON CWE-400 6.3 Medium2026-08-01
CVE-2026-44486 Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection CWE-200 7.5 High2026-06-11
CVE-2026-44487 Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter CWE-201 8.2 High2026-06-11
CVE-2026-44488 Axios: Allocation of Resources Without Limits or Throttling in axios CWE-770 7.5 High2026-06-11
CVE-2026-44490 Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions CWE-1321 4.8 Medium2026-06-11
CVE-2026-44496 Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection CWE-400 7.5 High2026-06-11
CVE-2026-44495 Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge CWE-94 7.0 High2026-06-11
CVE-2026-44494 Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` CWE-441 8.7 High2026-06-11
CVE-2026-44489 Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix CWE-113 3.7 Low2026-06-11
CVE-2026-44492 Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) CWE-918 8.6 High2026-06-11
CVE-2026-42264 Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking CWE-1321 7.4 High2026-05-08
CVE-2026-42042 Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion CWE-183 5.4 Medium2026-04-24
CVE-2026-42039 Axios: unbounded recursion in toFormData causes DoS via deeply nested request data CWE-674 6.9 Medium2026-04-24
CVE-2026-42036 Axios: HTTP adapter streamed responses bypass maxContentLength CWE-770 5.3 Medium2026-04-24
CVE-2026-42034 Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0 CWE-770 5.3 Medium2026-04-24
CVE-2026-42037 Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream CWE-93 5.3 Medium2026-04-24
CVE-2026-42038 Axios: no_proxy bypass via IP alias allows SSRF CWE-918 6.8 Medium2026-04-24
CVE-2026-42041 Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy CWE-287 4.8 Medium2026-04-24
CVE-2026-42043 Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 CWE-183 7.2 High2026-04-24
CVE-2026-42044 Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` CWE-915 6.5 Medium2026-04-24
CVE-2026-42040 Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams CWE-116 3.7 Low2026-04-24

All 40 known CVE vulnerabilities affecting axios with full Chinese analysis, references, and POCs where available.