Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-j8rh-479h-cp32
  • npm/axios
Axios: Header Injection via Inherited headers After Minimal Interceptor yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-4hqw-qxg8-jxx2
  • npm/axios
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-m8m8-qj5v-23w3
  • npm/axios
Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection yesterday
  • Fix available
  • Severity - 7.6 (High)
GHSA-44g4-m2mj-wpvx
  • npm/axios
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-r4gj-5m52-g5wh
  • npm/axios
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF yesterday
  • Fix available
  • Severity - 7.0 (High)
GHSA-vh66-26gq-q6x8
  • npm/axios
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-9fr6-4gfg-395g
  • npm/axios
Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-c29m-xwm3-cm6r
  • npm/axios
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) yesterday
  • Fix available
  • Severity - 8.2 (High)
GHSA-mghh-pgcx-3jjj
  • npm/axios
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location yesterday
  • Fix available
  • Severity - 8.2 (High)
GHSA-x97p-jq2g-jp4f
  • npm/axios
Axios: Prototype Pollution Gadget in axios toFormData Options yesterday
  • Fix available
  • Severity - 8.3 (High)
GHSA-3pq3-5fj3-cg6v
  • npm/axios
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls yesterday
  • Fix available
  • Severity - 7.0 (High)
GHSA-542g-h47m-68v8
  • npm/axios
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization yesterday
  • Fix available
  • Severity - 8.2 (High)
MAL-2026-14029
  • npm/axios-fast
Malicious code in axios-fast (npm) 14 Aug
  • No fix available
MAL-2026-11030
  • npm/vitest-axios
Malicious code in vitest-axios (npm) 23 Jul
  • No fix available
GHSA-gcfj-64vw-6mp9
  • npm/axios
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning 20 Jul
  • Fix available
  • Severity - 8.3 (High)
GHSA-hcpx-6fm6-wx23
  • npm/axios
Axios form serializer maxDepth bypass via {} metatoken 20 Jul
  • Fix available
  • Severity - 6.9 (Medium)