axios vulnerabilities and security advisories
The newest reviewed advisories for axios on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.
Get an email when axios has a new one
Email alerts are coming soon. This page updates every hour.
$ latest 30 · 18 critical, high or exploited
- highJul 20, 2026
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
- axios >= 0.31.1, < 0.33.0 · fixed in 0.33.0
- axios >= 1.15.2, < 1.18.0 · fixed in 1.18.0
GHSA-gcfj-64vw-6mp9CVE-2026-67320prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-gcfj-64vw-6mp9 (CVE-2026-67320), severity high What it is: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning Affected packages: - axios: affected versions >= 0.31.1, < 0.33.0. Fixed in 0.33.0. - axios: affected versions >= 1.15.2, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-gcfj-64vw-6mp9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios form serializer maxDepth bypass via {} metatoken
- axios >= 0.31.1, < 0.33.0 · fixed in 0.33.0
- axios >= 1.15.1, < 1.18.0 · fixed in 1.18.0
GHSA-hcpx-6fm6-wx23CVE-2026-67321prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hcpx-6fm6-wx23 (CVE-2026-67321), severity medium What it is: Axios form serializer maxDepth bypass via {} metatoken Affected packages: - axios: affected versions >= 0.31.1, < 0.33.0. Fixed in 0.33.0. - axios: affected versions >= 1.15.1, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-hcpx-6fm6-wx23 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: Nested axios option objects can consume polluted prototype values
- axios >= 0.8.0, < 0.33.0 · fixed in 0.33.0
- axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
GHSA-7q8q-rj6j-mhjqCVE-2026-67319prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-7q8q-rj6j-mhjq (CVE-2026-67319), severity medium What it is: Axios: Nested axios option objects can consume polluted prototype values Affected packages: - axios: affected versions >= 0.8.0, < 0.33.0. Fixed in 0.33.0. - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-7q8q-rj6j-mhjq Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
- axios >= 1.13.0, < 1.18.0 · fixed in 1.18.0
GHSA-mwf2-3pr3-8698CVE-2026-67318prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-mwf2-3pr3-8698 (CVE-2026-67318), severity medium What it is: Axios: HTTP/2 streamed uploads bypass `maxBodyLength` Affected packages: - axios: affected versions >= 1.13.0, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-mwf2-3pr3-8698 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
- axios >= 1.7.0, < 1.18.0 · fixed in 1.18.0
GHSA-jqh4-m9w3-8hp9CVE-2026-67317prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-jqh4-m9w3-8hp9 (CVE-2026-67317), severity medium What it is: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` Affected packages: - axios: affected versions >= 1.7.0, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-jqh4-m9w3-8hp9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: Prototype pollution gadgets can alter axios request construction
- axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
- axios < 0.33.0 · fixed in 0.33.0
GHSA-mmx7-hfxf-jppxCVE-2026-67316prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-mmx7-hfxf-jppx (CVE-2026-67316), severity medium What it is: Axios: Prototype pollution gadgets can alter axios request construction Affected packages: - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0. - axios: affected versions < 0.33.0. Fixed in 0.33.0. Details: https://github.com/advisories/GHSA-mmx7-hfxf-jppx Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
- axios >= 1.15.0, < 1.18.0 · fixed in 1.18.0
- axios >= 0.31.0, < 0.33.0 · fixed in 0.33.0
GHSA-f4gw-2p7v-4548CVE-2026-67315prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-f4gw-2p7v-4548 (CVE-2026-67315), severity medium What it is: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios Affected packages: - axios: affected versions >= 1.15.0, < 1.18.0. Fixed in 1.18.0. - axios: affected versions >= 0.31.0, < 0.33.0. Fixed in 0.33.0. Details: https://github.com/advisories/GHSA-f4gw-2p7v-4548 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: Excessive recursion in formDataToJSON can cause denial of service
- axios >= 0.28.0, < 0.33.0 · fixed in 0.33.0
- axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
GHSA-42h9-826w-cgv3CVE-2026-67313prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-42h9-826w-cgv3 (CVE-2026-67313), severity medium What it is: Axios: Excessive recursion in formDataToJSON can cause denial of service Affected packages: - axios: affected versions >= 0.28.0, < 0.33.0. Fixed in 0.33.0. - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-42h9-826w-cgv3 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: Prototype pollution auth subfields can inject Basic auth
- axios >= 1.15.2, < 1.18.0 · fixed in 1.18.0
GHSA-xj6q-8x83-jv6gCVE-2026-67314prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-xj6q-8x83-jv6g (CVE-2026-67314), severity medium What it is: Axios: Prototype pollution auth subfields can inject Basic auth Affected packages: - axios: affected versions >= 1.15.2, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-xj6q-8x83-jv6g Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
- axios >= 0.28.0, < 0.33.0 · fixed in 0.33.0
- axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
GHSA-pmv8-rq9r-6j72CVE-2026-67312prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-pmv8-rq9r-6j72 (CVE-2026-67312), severity medium What it is: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service Affected packages: - axios: affected versions >= 0.28.0, < 0.33.0. Fixed in 0.33.0. - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0. Details: https://github.com/advisories/GHSA-pmv8-rq9r-6j72 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 4, 2026
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
- axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
- axios <= 0.31.1 · fixed in 0.32.0
GHSA-hfxv-24rg-xrqfCVE-2026-44496prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hfxv-24rg-xrqf (CVE-2026-44496), severity high What it is: Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection Affected packages: - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0. - axios: affected versions <= 0.31.1. Fixed in 0.32.0. Details: https://github.com/advisories/GHSA-hfxv-24rg-xrqf Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 4, 2026
Allocation of Resources Without Limits or Throttling in Axios
- axios >= 1.7.0, < 1.16.0 · fixed in 1.16.0
GHSA-777c-7fjr-54vfCVE-2026-44488prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-777c-7fjr-54vf (CVE-2026-44488), severity high What it is: Allocation of Resources Without Limits or Throttling in Axios Affected packages: - axios: affected versions >= 1.7.0, < 1.16.0. Fixed in 1.16.0. Details: https://github.com/advisories/GHSA-777c-7fjr-54vf Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 4, 2026
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
- axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
- axios <= 0.31.1 · fixed in 0.32.0
GHSA-p92q-9vqr-4j8vCVE-2026-44487prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-p92q-9vqr-4j8v (CVE-2026-44487), severity high What it is: Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter Affected packages: - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0. - axios: affected versions <= 0.31.1. Fixed in 0.32.0. Details: https://github.com/advisories/GHSA-p92q-9vqr-4j8v Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 4, 2026
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
- axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
- axios <= 0.31.1 · fixed in 0.32.0
GHSA-j5f8-grm9-p9fcCVE-2026-44486prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-j5f8-grm9-p9fc (CVE-2026-44486), severity high What it is: Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection Affected packages: - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0. - axios: affected versions <= 0.31.1. Fixed in 0.32.0. Details: https://github.com/advisories/GHSA-j5f8-grm9-p9fc Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 29, 2026
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
- axios >= 1.0.0, < 1.15.2 · fixed in 1.15.2
- axios >= 0.19.0, < 0.31.1 · fixed in 0.31.1
GHSA-3g43-6gmg-66jwCVE-2026-44495prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-3g43-6gmg-66jw (CVE-2026-44495), severity high What it is: axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge Affected packages: - axios: affected versions >= 1.0.0, < 1.15.2. Fixed in 1.15.2. - axios: affected versions >= 0.19.0, < 0.31.1. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-3g43-6gmg-66jw Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 29, 2026
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
- axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
GHSA-35jp-ww65-95whCVE-2026-44494prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-35jp-ww65-95wh (CVE-2026-44494), severity high What it is: axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` Affected packages: - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0. Details: https://github.com/advisories/GHSA-35jp-ww65-95wh Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 29, 2026
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
- axios <= 0.31.1 · fixed in 0.32.0
- axios >= 1.15.0, < 1.16.0 · fixed in 1.16.0
GHSA-pjwm-pj3p-43mvCVE-2026-44492prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-pjwm-pj3p-43mv (CVE-2026-44492), severity high What it is: axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) Affected packages: - axios: affected versions <= 0.31.1. Fixed in 0.32.0. - axios: affected versions >= 1.15.0, < 1.16.0. Fixed in 1.16.0. Details: https://github.com/advisories/GHSA-pjwm-pj3p-43mv Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 29, 2026
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
- axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
- axios <= 0.31.1 · fixed in 0.32.0
GHSA-898c-q2cr-xwhgCVE-2026-44490prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-898c-q2cr-xwhg (CVE-2026-44490), severity medium What it is: axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions Affected packages: - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0. - axios: affected versions <= 0.31.1. Fixed in 0.32.0. Details: https://github.com/advisories/GHSA-898c-q2cr-xwhg Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowMay 29, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- axios = 1.15.2 · fixed in 1.16.0
GHSA-654m-c8p4-x5fpCVE-2026-44489prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-654m-c8p4-x5fp (CVE-2026-44489), severity low What it is: Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix Affected packages: - axios: affected versions = 1.15.2. Fixed in 1.16.0. Details: https://github.com/advisories/GHSA-654m-c8p4-x5fp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
GHSA-445q-vr5w-6q77CVE-2026-42037prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-445q-vr5w-6q77 (CVE-2026-42037), severity medium What it is: Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. Details: https://github.com/advisories/GHSA-445q-vr5w-6q77 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: no_proxy bypass via IP alias allows SSRF
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-m7pr-hjqh-92cmCVE-2026-42038prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-m7pr-hjqh-92cm (CVE-2026-42038), severity medium What it is: Axios: no_proxy bypass via IP alias allows SSRF Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-m7pr-hjqh-92cm Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-62hf-57xw-28j9CVE-2026-42039prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-62hf-57xw-28j9 (CVE-2026-42039), severity medium What it is: Axios: unbounded recursion in toFormData causes DoS via deeply nested request data Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-62hf-57xw-28j9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-5c9x-8gcm-mpgxCVE-2026-42034prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-5c9x-8gcm-mpgx (CVE-2026-42034), severity medium What it is: Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0 Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-5c9x-8gcm-mpgx Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: HTTP adapter streamed responses bypass maxContentLength
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-vf2m-468p-8v99CVE-2026-42036prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-vf2m-468p-8v99 (CVE-2026-42036), severity medium What it is: Axios: HTTP adapter streamed responses bypass maxContentLength Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-vf2m-468p-8v99 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 5, 2026
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-pf86-5x62-jrwfCVE-2026-42033prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-pf86-5x62-jrwf (CVE-2026-42033), severity high What it is: Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-pf86-5x62-jrwf Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 5, 2026
Axios: Header Injection via Prototype Pollution
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-6chq-wfr3-2hj9CVE-2026-42035prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-6chq-wfr3-2hj9 (CVE-2026-42035), severity high What it is: Axios: Header Injection via Prototype Pollution Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-6chq-wfr3-2hj9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-xx6v-rp6x-q39cCVE-2026-42042prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-xx6v-rp6x-q39c (CVE-2026-42042), severity medium What it is: Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-xx6v-rp6x-q39c Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-w9j2-pvgh-6h63CVE-2026-42041prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-w9j2-pvgh-6h63 (CVE-2026-42041), severity medium What it is: Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-w9j2-pvgh-6h63 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highMay 5, 2026
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
- axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
- axios <= 0.31.0 · fixed in 0.31.1
GHSA-pmwg-cvhr-8vh7CVE-2026-42043prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-pmwg-cvhr-8vh7 (CVE-2026-42043), severity high What it is: Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 Affected packages: - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1. - axios: affected versions <= 0.31.0. Fixed in 0.31.1. Details: https://github.com/advisories/GHSA-pmwg-cvhr-8vh7 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMay 5, 2026
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
- axios >= 1.0.0, < 1.15.2 · fixed in 1.15.2
GHSA-3w6x-2g7m-8v23CVE-2026-42044prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-3w6x-2g7m-8v23 (CVE-2026-42044), severity medium What it is: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` Affected packages: - axios: affected versions >= 1.0.0, < 1.15.2. Fixed in 1.15.2. Details: https://github.com/advisories/GHSA-3w6x-2g7m-8v23 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now.
From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.
Keeping axios patched
npm audit(orpnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.- Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
- A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.