Promise based HTTP client for the browser and node.js
npmlibraryAxios

Overview

Canonical component data stored by Polaris.

Version

1.10.0

Package Manager

npm

Type

library

Systems

1

Licenses
MIT
Direct Dependencies

3

Technology

Axios

External Signals
deps.dev endoflife.date OSV.dev
Package URL

pkg:npm/[email protected]

Maintenance

Derived from available component and registry data

Aging
Confidence

Medium

Version Age

418 days

Update Status

Minor update available

Recent Activity

Yes

Reasons
Old versionMature versionMinor available

Lifecycle

Source: endoflife.date

Unknown
No lifecycle match available
The mapped product was not available from the third-party lifecycle source.
Open endoflife.date

Known Vulnerabilities

Source: OSV.dev

29 found

GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected Versions
>= 1.0.0, before 1.16.0
Open advisory

GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Affected Versions
>= 1.0.0, before 1.15.2>= 0.19.0, before 0.31.1
Open advisory

GHSA-3p68-rc4w-qgx5

Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.0all versions before 0.31.0
Open advisory

GHSA-3w6x-2g7m-8v23

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Affected Versions
>= 1.0.0, before 1.15.2
Open advisory

GHSA-42h9-826w-cgv3

Axios: Excessive recursion in formDataToJSON can cause denial of service

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Versions
>= 0.28.0, before 0.33.0>= 1.0.0, before 1.18.0
Open advisory

GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 1.0.0, before 1.13.5all versions before 0.30.3
Open advisory

GHSA-445q-vr5w-6q77

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.1
Open advisory

GHSA-4hjh-wcwx-xvwj

Axios is vulnerable to DoS attack through lack of data size check

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 1.0.0, before 1.12.0>= 0.28.0, before 0.30.2
Open advisory

GHSA-5c9x-8gcm-mpgx

Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-62hf-57xw-28j9

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-6chq-wfr3-2hj9

Axios: Header Injection via Prototype Pollution

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-777c-7fjr-54vf

Allocation of Resources Without Limits or Throttling in Axios

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 1.7.0, before 1.16.0
Open advisory

GHSA-7q8q-rj6j-mhjq

Axios: Nested axios option objects can consume polluted prototype values

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Affected Versions
>= 0.8.0, before 0.33.0>= 1.0.0, before 1.18.0
Open advisory

GHSA-898c-q2cr-xwhg

axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Affected Versions
>= 1.0.0, before 1.16.0all versions before 0.32.0
Open advisory

GHSA-fvcv-3m26-pcqx

Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.0all versions before 0.31.0
Open advisory

GHSA-hfxv-24rg-xrqf

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
>= 1.0.0, before 1.16.0all versions before 0.32.0
Open advisory

GHSA-j5f8-grm9-p9fc

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Versions
>= 1.0.0, before 1.16.0all versions before 0.32.0
Open advisory

GHSA-jqh4-m9w3-8hp9

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Affected Versions
>= 1.7.0, before 1.18.0
Open advisory

GHSA-m7pr-hjqh-92cm

Axios: no_proxy bypass via IP alias allows SSRF

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-mmx7-hfxf-jppx

Axios: Prototype pollution gadgets can alter axios request construction

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Versions
>= 1.0.0, before 1.18.0all versions before 0.33.0
Open advisory

GHSA-p92q-9vqr-4j8v

Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Versions
>= 1.0.0, before 1.16.0all versions before 0.32.0
Open advisory

GHSA-pf86-5x62-jrwf

Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-pmv8-rq9r-6j72

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected Versions
>= 0.28.0, before 0.33.0>= 1.0.0, before 1.18.0
Open advisory

GHSA-pmwg-cvhr-8vh7

Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-q8qp-cvcw-x6jj

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Versions
>= 1.0.0, before 1.15.2
Open advisory

GHSA-vf2m-468p-8v99

Axios: HTTP adapter streamed responses bypass maxContentLength

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-w9j2-pvgh-6h63

Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-xhjh-pmcv-23jw

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory

GHSA-xx6v-rp6x-q39c

Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Affected Versions
>= 1.0.0, before 1.15.1all versions before 0.31.1
Open advisory
Open OSV.dev

Security

Source: OpenSSF Scorecard

Unavailable
No security scorecard available
This component does not have a repository reference for OpenSSF Scorecard lookup.

Dependencies

3 direct dependencies

Global view