axios
Overview
Canonical component data stored by Polaris.
1.10.0
npm
library
1
3
pkg:npm/[email protected]
Maintenance
Derived from available component and registry data
Medium
418 days
Minor update available
Yes
Lifecycle
Source: endoflife.date
Registry
Source: deps.dev
npm
1.19.0
6/14/2025
26
29
Known Vulnerabilities
Source: OSV.dev
GHSA-35jp-ww65-95wh
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
GHSA-3g43-6gmg-66jw
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
GHSA-3p68-rc4w-qgx5
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
GHSA-3w6x-2g7m-8v23
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
GHSA-42h9-826w-cgv3
Axios: Excessive recursion in formDataToJSON can cause denial of service
GHSA-43fc-jf86-j433
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
GHSA-445q-vr5w-6q77
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
GHSA-4hjh-wcwx-xvwj
Axios is vulnerable to DoS attack through lack of data size check
GHSA-5c9x-8gcm-mpgx
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
GHSA-62hf-57xw-28j9
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
GHSA-6chq-wfr3-2hj9
Axios: Header Injection via Prototype Pollution
GHSA-777c-7fjr-54vf
Allocation of Resources Without Limits or Throttling in Axios
GHSA-7q8q-rj6j-mhjq
Axios: Nested axios option objects can consume polluted prototype values
GHSA-898c-q2cr-xwhg
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
GHSA-fvcv-3m26-pcqx
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
GHSA-hfxv-24rg-xrqf
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
GHSA-j5f8-grm9-p9fc
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
GHSA-jqh4-m9w3-8hp9
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
GHSA-m7pr-hjqh-92cm
Axios: no_proxy bypass via IP alias allows SSRF
GHSA-mmx7-hfxf-jppx
Axios: Prototype pollution gadgets can alter axios request construction
GHSA-p92q-9vqr-4j8v
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
GHSA-pf86-5x62-jrwf
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
GHSA-pmv8-rq9r-6j72
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
GHSA-pmwg-cvhr-8vh7
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
GHSA-q8qp-cvcw-x6jj
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
GHSA-vf2m-468p-8v99
Axios: HTTP adapter streamed responses bypass maxContentLength
GHSA-w9j2-pvgh-6h63
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
GHSA-xhjh-pmcv-23jw
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
GHSA-xx6v-rp6x-q39c
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Security
Source: OpenSSF Scorecard
Systems (1)
Dependencies
3 direct dependencies