Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2230377
AlmaLinux
5964
Alpaquita
16124
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
762
Bitnami
9476
Chainguard
1042229
CleanStart
5179
CRAN
14
crates.io
2746
Debian
68788
Echo
7618
GHC
3
GIT
108628
GitHub Actions
55
Go
9254
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6233
Maven
7048
MinimOS
147097
npm
229049
NuGet
1869
opam
29
openEuler
8900
openSUSE
14509
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25414
Red Hat
23452
Rocky Linux
4328
Root
19620
RubyGems
5326
SUSE
23401
SwiftURL
60
TuxCare
9722
Ubuntu
65803
VSCode
21
Wolfi
292367
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-j8rh-479h-cp32
npm/axios
Axios: Header Injection via Inherited headers After Minimal Interceptor
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-4hqw-qxg8-jxx2
npm/axios
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-m8m8-qj5v-23w3
npm/axios
Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
yesterday
Fix available
Severity - 7.6 (High)
GHSA-44g4-m2mj-wpvx
npm/axios
Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-r4gj-5m52-g5wh
npm/axios
Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
yesterday
Fix available
Severity - 7.0 (High)
GHSA-vh66-26gq-q6x8
npm/axios
Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-9fr6-4gfg-395g
npm/axios
Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
yesterday
Fix available
Severity - 6.9 (Medium)
GHSA-c29m-xwm3-cm6r
npm/axios
Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
yesterday
Fix available
Severity - 8.2 (High)
GHSA-mghh-pgcx-3jjj
npm/axios
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
yesterday
Fix available
Severity - 8.2 (High)
GHSA-x97p-jq2g-jp4f
npm/axios
Axios: Prototype Pollution Gadget in axios toFormData Options
yesterday
Fix available
Severity - 8.3 (High)
GHSA-3pq3-5fj3-cg6v
npm/axios
Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
yesterday
Fix available
Severity - 7.0 (High)
GHSA-542g-h47m-68v8
npm/axios
Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
yesterday
Fix available
Severity - 8.2 (High)
MAL-2026-14029
npm/axios-fast
Malicious code in axios-fast (npm)
14 Aug
No fix available
MAL-2026-11030
npm/vitest-axios
Malicious code in vitest-axios (npm)
23 Jul
No fix available
GHSA-gcfj-64vw-6mp9
npm/axios
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
20 Jul
Fix available
Severity - 8.3 (High)
GHSA-hcpx-6fm6-wx23
npm/axios
Axios form serializer maxDepth bypass via {} metatoken
20 Jul
Fix available
Severity - 6.9 (Medium)
Load more...
npm - OSV