Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

axios — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting axios. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Axios is a widely adopted HTTP client for JavaScript environments, primarily utilized in browser and Node.js applications to simplify asynchronous data fetching. Despite its popularity, the library has faced 21 recorded Common Vulnerabilities and Exposures (CVEs), predominantly stemming from improper input validation and prototype pollution issues. These flaws often enable remote code execution or cross-site scripting attacks when user-controlled data is passed directly into configuration objects without sanitization. Notably, several vulnerabilities allowed attackers to bypass security controls by manipulating internal headers or request parameters. While Axios itself does not store data, its widespread integration into frontend frameworks makes it a frequent target for supply chain attacks. Developers must ensure strict input validation and keep dependencies updated to mitigate risks associated with these historical security gaps, particularly in applications handling sensitive user information.

Top products by axios: axios axios/axios
High2026-05-08
fix: more header pollutions (#10779) · axios/axios@4791514 · GitHub
HighGHSA-q8qp-cvcw-x6jg2026-05-08
fix: more header pollutions by jasonsaayman · Pull Request #10779 · axios/axios · GitHub
High2026-05-08
Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking · Advisory · axio
High2026-05-08
Release v1.15.2 · axios/axios · GitHub
High2026-04-25
Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy · Advisory · axios/axios · GitHu
HighCVE-2025-627182026-04-25
[Patch Bypass] Incomplete Fix for GHSA-3p68-rc4w-qgx5 (CVE-2025-62718) — NO_PROXY Protection Bypassed via RFC 1122 Loopb
Critical2026-04-25
Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` · Advisory · axios/axios · GitHub
Medium2026-04-25
CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream · Advisory · axios/axios · GitH
MediumCVE-2026-42422026-04-25
XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion · Advisory · axios/ax
MediumCVE-2024-205342026-04-25
HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0 · Advisory · axios/axios · GitHub
MediumCVE-2026-420392026-04-25
axios: unbounded recursion in toFormData causes DoS via deeply nested request data · Advisory · axios/axios · GitHub
MediumCVE-2026-425382026-04-25
no_proxy bypass via IP alias allows SSRF · Advisory · axios/axios · GitHub
Medium2026-04-25
HTTP adapter streamed responses bypass maxContentLength · Advisory · axios/axios · GitHub
High2026-04-25
Prototype Pollution Gadgets in axios: Response Tampering, Data Exfiltration, and Request Hijacking · Advisory · axios/ax
HighCVE-2024-20352026-04-25
Header Injection via Prototype Pollution · Advisory · axios/axios · GitHub
Low2026-04-25
Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams · Advisory · axios/axios · GitHub
Unknown2026-04-18
fix: backport the fixes from the v1 branch (#10688) · axios/axios@03cdfc9 · GitHub
High2026-04-18
fix: backport the fixes from the v1 branch by jasonsaayman · Pull Request #10688 · axios/axios · GitHub
High2026-04-11
fix: unrestricted cloud metadata exfiltration via header injection chain by jasonsaayman · Pull Request #10660 · axios/a
High2026-04-10
fix: no_proxy hostname normalization bypass leads to ssrf (#10661) · axios/axios@fb3befb · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with axios. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.