Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-44494 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Polluti… Axios 1.16.0+ Fix from $1,9502026-06-11 HIGH 8.6 CVE-2026-44492 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. Wh… Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 HIGH 8.2 CVE-2026-44490 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets… Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-44496 Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line buil… Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-44487 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Author… Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-44486 Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials … Axios 0.32.0 / 1.16.0+ Fix from $1,9502026-06-11 HIGH 7.5 CVE-2026-44488 Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response… Axios 1.16.0+ Fix from $1,9502026-06-11 MEDIUM 5.3 CVE-2026-44489 Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config… Axios No fix yet Fix from $1,6002026-06-11 CRITICAL 9.1 CVE-2026-42264 Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL… Axios 1.15.2+ Fix from $2,3002026-05-08 CRITICAL 10.0 CVE-2026-42043 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio… Axios 0.31.1 / 1.15.1+ Fix from $2,3002026-04-24 CRITICAL 9.1 CVE-2026-42044 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollutio… Axios 1.15.1+ Fix from $2,3002026-04-24 MEDIUM 6.5 CVE-2026-42041 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollutio… Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 MEDIUM 5.4 CVE-2026-42042 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses Ja… Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 HIGH 7.5 CVE-2026-42039 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no dep… Axios 0.31.1 / 1.15.1+ Fix from $1,9502026-04-24 HIGH 7.5 CVE-2026-42038 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is in… Axios 0.31.1 / 1.15.1+ Fix from $1,9502026-04-24 HIGH 7.4 CVE-2026-42035 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP a… Axios 0.31.1 / 1.15.1+ Fix from $1,9502026-04-24 MEDIUM 5.3 CVE-2026-42034 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed wh… Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 MEDIUM 5.3 CVE-2026-42036 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the … Axios 0.31.1 / 1.15.1+ Fix from $1,6002026-04-24 MEDIUM 5.3 CVE-2026-42037 Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataTo… Axios 1.15.1+ Fix from $1,6002026-04-24 HIGH 7.4 CVE-2026-42033 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-depen… Axios 0.31.1 / 1.15.1+ Fix from $1,9502026-04-24 CRITICAL 9.9 CVE-2025-62718 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization … Axios 0.31.0 / 1.15.0+ Fix from $2,3002026-04-09 MEDIUM 5.9 CVE-2026-39865 Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic … Axios 1.13.2+ Fix from $1,6002026-04-08 HIGH 7.5 CVE-2026-25639 Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with… Axios 0.30.3 / 1.13.5+ Fix from $1,9502026-02-09 HIGH 7.5 CVE-2025-58754 Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs … Axios 0.30.2 / 1.12.0+ Fix from $1,9502025-09-12 MEDIUM 5.3 CVE-2025-27152 axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to a… Axios 0.30.0+ Fix from $1,6002025-03-07 CRITICAL 9.8 CVE-2024-57965 In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribu… Axios 1.7.8+ Fix from $2,3002025-01-29 HIGH 7.5 CVE-2024-39338 axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. Axios 1.7.4+ Fix from $1,9502024-08-12 MEDIUM 6.5 CVE-2023-45857 An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKE… Axios No fix yet Fix from $1,6002023-11-08 HIGH 7.5 CVE-2021-3749EPSS 9% axios is vulnerable to Inefficient Regular Expression Complexity Axios 1.0 / 21.7.0.0.0+ Fix from $1,9502021-08-31 MEDIUM 5.9 CVE-2020-28168 Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL t… Axios 1.0+ Fix from $1,6002020-11-06