pwnmyvibecode_

axios vulnerabilities and security advisories

The newest reviewed advisories for axios on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.

Get an email when axios has a new one

Email alerts are coming soon. This page updates every hour.

$ latest 30 · 18 critical, high or exploited

  • highJul 20, 2026

    Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

    • axios >= 0.31.1, < 0.33.0 · fixed in 0.33.0
    • axios >= 1.15.2, < 1.18.0 · fixed in 1.18.0
    GHSA-gcfj-64vw-6mp9CVE-2026-67320
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-gcfj-64vw-6mp9 (CVE-2026-67320), severity high
    What it is: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
    Affected packages:
    - axios: affected versions >= 0.31.1, < 0.33.0. Fixed in 0.33.0.
    - axios: affected versions >= 1.15.2, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-gcfj-64vw-6mp9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios form serializer maxDepth bypass via {} metatoken

    • axios >= 0.31.1, < 0.33.0 · fixed in 0.33.0
    • axios >= 1.15.1, < 1.18.0 · fixed in 1.18.0
    GHSA-hcpx-6fm6-wx23CVE-2026-67321
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hcpx-6fm6-wx23 (CVE-2026-67321), severity medium
    What it is: Axios form serializer maxDepth bypass via {} metatoken
    Affected packages:
    - axios: affected versions >= 0.31.1, < 0.33.0. Fixed in 0.33.0.
    - axios: affected versions >= 1.15.1, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-hcpx-6fm6-wx23
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: Nested axios option objects can consume polluted prototype values

    • axios >= 0.8.0, < 0.33.0 · fixed in 0.33.0
    • axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
    GHSA-7q8q-rj6j-mhjqCVE-2026-67319
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-7q8q-rj6j-mhjq (CVE-2026-67319), severity medium
    What it is: Axios: Nested axios option objects can consume polluted prototype values
    Affected packages:
    - axios: affected versions >= 0.8.0, < 0.33.0. Fixed in 0.33.0.
    - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-7q8q-rj6j-mhjq
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

    • axios >= 1.13.0, < 1.18.0 · fixed in 1.18.0
    GHSA-mwf2-3pr3-8698CVE-2026-67318
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-mwf2-3pr3-8698 (CVE-2026-67318), severity medium
    What it is: Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
    Affected packages:
    - axios: affected versions >= 1.13.0, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-mwf2-3pr3-8698
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

    • axios >= 1.7.0, < 1.18.0 · fixed in 1.18.0
    GHSA-jqh4-m9w3-8hp9CVE-2026-67317
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-jqh4-m9w3-8hp9 (CVE-2026-67317), severity medium
    What it is: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
    Affected packages:
    - axios: affected versions >= 1.7.0, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-jqh4-m9w3-8hp9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: Prototype pollution gadgets can alter axios request construction

    • axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
    • axios < 0.33.0 · fixed in 0.33.0
    GHSA-mmx7-hfxf-jppxCVE-2026-67316
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-mmx7-hfxf-jppx (CVE-2026-67316), severity medium
    What it is: Axios: Prototype pollution gadgets can alter axios request construction
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0.
    - axios: affected versions < 0.33.0. Fixed in 0.33.0.
    Details: https://github.com/advisories/GHSA-mmx7-hfxf-jppx
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

    • axios >= 1.15.0, < 1.18.0 · fixed in 1.18.0
    • axios >= 0.31.0, < 0.33.0 · fixed in 0.33.0
    GHSA-f4gw-2p7v-4548CVE-2026-67315
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-f4gw-2p7v-4548 (CVE-2026-67315), severity medium
    What it is: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
    Affected packages:
    - axios: affected versions >= 1.15.0, < 1.18.0. Fixed in 1.18.0.
    - axios: affected versions >= 0.31.0, < 0.33.0. Fixed in 0.33.0.
    Details: https://github.com/advisories/GHSA-f4gw-2p7v-4548
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: Excessive recursion in formDataToJSON can cause denial of service

    • axios >= 0.28.0, < 0.33.0 · fixed in 0.33.0
    • axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
    GHSA-42h9-826w-cgv3CVE-2026-67313
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-42h9-826w-cgv3 (CVE-2026-67313), severity medium
    What it is: Axios: Excessive recursion in formDataToJSON can cause denial of service
    Affected packages:
    - axios: affected versions >= 0.28.0, < 0.33.0. Fixed in 0.33.0.
    - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-42h9-826w-cgv3
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: Prototype pollution auth subfields can inject Basic auth

    • axios >= 1.15.2, < 1.18.0 · fixed in 1.18.0
    GHSA-xj6q-8x83-jv6gCVE-2026-67314
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-xj6q-8x83-jv6g (CVE-2026-67314), severity medium
    What it is: Axios: Prototype pollution auth subfields can inject Basic auth
    Affected packages:
    - axios: affected versions >= 1.15.2, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-xj6q-8x83-jv6g
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJul 20, 2026

    Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

    • axios >= 0.28.0, < 0.33.0 · fixed in 0.33.0
    • axios >= 1.0.0, < 1.18.0 · fixed in 1.18.0
    GHSA-pmv8-rq9r-6j72CVE-2026-67312
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-pmv8-rq9r-6j72 (CVE-2026-67312), severity medium
    What it is: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
    Affected packages:
    - axios: affected versions >= 0.28.0, < 0.33.0. Fixed in 0.33.0.
    - axios: affected versions >= 1.0.0, < 1.18.0. Fixed in 1.18.0.
    Details: https://github.com/advisories/GHSA-pmv8-rq9r-6j72
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJun 4, 2026

    Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

    • axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
    • axios <= 0.31.1 · fixed in 0.32.0
    GHSA-hfxv-24rg-xrqfCVE-2026-44496
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hfxv-24rg-xrqf (CVE-2026-44496), severity high
    What it is: Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0.
    - axios: affected versions <= 0.31.1. Fixed in 0.32.0.
    Details: https://github.com/advisories/GHSA-hfxv-24rg-xrqf
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJun 4, 2026

    Allocation of Resources Without Limits or Throttling in Axios

    • axios >= 1.7.0, < 1.16.0 · fixed in 1.16.0
    GHSA-777c-7fjr-54vfCVE-2026-44488
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-777c-7fjr-54vf (CVE-2026-44488), severity high
    What it is: Allocation of Resources Without Limits or Throttling in Axios
    Affected packages:
    - axios: affected versions >= 1.7.0, < 1.16.0. Fixed in 1.16.0.
    Details: https://github.com/advisories/GHSA-777c-7fjr-54vf
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJun 4, 2026

    Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

    • axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
    • axios <= 0.31.1 · fixed in 0.32.0
    GHSA-p92q-9vqr-4j8vCVE-2026-44487
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-p92q-9vqr-4j8v (CVE-2026-44487), severity high
    What it is: Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0.
    - axios: affected versions <= 0.31.1. Fixed in 0.32.0.
    Details: https://github.com/advisories/GHSA-p92q-9vqr-4j8v
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJun 4, 2026

    Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

    • axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
    • axios <= 0.31.1 · fixed in 0.32.0
    GHSA-j5f8-grm9-p9fcCVE-2026-44486
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-j5f8-grm9-p9fc (CVE-2026-44486), severity high
    What it is: Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0.
    - axios: affected versions <= 0.31.1. Fixed in 0.32.0.
    Details: https://github.com/advisories/GHSA-j5f8-grm9-p9fc
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 29, 2026

    axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

    • axios >= 1.0.0, < 1.15.2 · fixed in 1.15.2
    • axios >= 0.19.0, < 0.31.1 · fixed in 0.31.1
    GHSA-3g43-6gmg-66jwCVE-2026-44495
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-3g43-6gmg-66jw (CVE-2026-44495), severity high
    What it is: axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.2. Fixed in 1.15.2.
    - axios: affected versions >= 0.19.0, < 0.31.1. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-3g43-6gmg-66jw
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 29, 2026

    axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

    • axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
    GHSA-35jp-ww65-95whCVE-2026-44494
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-35jp-ww65-95wh (CVE-2026-44494), severity high
    What it is: axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0.
    Details: https://github.com/advisories/GHSA-35jp-ww65-95wh
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 29, 2026

    axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

    • axios <= 0.31.1 · fixed in 0.32.0
    • axios >= 1.15.0, < 1.16.0 · fixed in 1.16.0
    GHSA-pjwm-pj3p-43mvCVE-2026-44492
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-pjwm-pj3p-43mv (CVE-2026-44492), severity high
    What it is: axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
    Affected packages:
    - axios: affected versions <= 0.31.1. Fixed in 0.32.0.
    - axios: affected versions >= 1.15.0, < 1.16.0. Fixed in 1.16.0.
    Details: https://github.com/advisories/GHSA-pjwm-pj3p-43mv
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 29, 2026

    axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

    • axios >= 1.0.0, < 1.16.0 · fixed in 1.16.0
    • axios <= 0.31.1 · fixed in 0.32.0
    GHSA-898c-q2cr-xwhgCVE-2026-44490
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-898c-q2cr-xwhg (CVE-2026-44490), severity medium
    What it is: axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.16.0. Fixed in 1.16.0.
    - axios: affected versions <= 0.31.1. Fixed in 0.32.0.
    Details: https://github.com/advisories/GHSA-898c-q2cr-xwhg
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • lowMay 29, 2026

    Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

    • axios = 1.15.2 · fixed in 1.16.0
    GHSA-654m-c8p4-x5fpCVE-2026-44489
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-654m-c8p4-x5fp (CVE-2026-44489), severity low
    What it is: Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
    Affected packages:
    - axios: affected versions = 1.15.2. Fixed in 1.16.0.
    Details: https://github.com/advisories/GHSA-654m-c8p4-x5fp
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    GHSA-445q-vr5w-6q77CVE-2026-42037
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-445q-vr5w-6q77 (CVE-2026-42037), severity medium
    What it is: Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    Details: https://github.com/advisories/GHSA-445q-vr5w-6q77
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: no_proxy bypass via IP alias allows SSRF

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-m7pr-hjqh-92cmCVE-2026-42038
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-m7pr-hjqh-92cm (CVE-2026-42038), severity medium
    What it is: Axios: no_proxy bypass via IP alias allows SSRF
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-m7pr-hjqh-92cm
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-62hf-57xw-28j9CVE-2026-42039
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-62hf-57xw-28j9 (CVE-2026-42039), severity medium
    What it is: Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-62hf-57xw-28j9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-5c9x-8gcm-mpgxCVE-2026-42034
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-5c9x-8gcm-mpgx (CVE-2026-42034), severity medium
    What it is: Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-5c9x-8gcm-mpgx
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: HTTP adapter streamed responses bypass maxContentLength

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-vf2m-468p-8v99CVE-2026-42036
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-vf2m-468p-8v99 (CVE-2026-42036), severity medium
    What it is: Axios: HTTP adapter streamed responses bypass maxContentLength
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-vf2m-468p-8v99
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 5, 2026

    Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-pf86-5x62-jrwfCVE-2026-42033
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-pf86-5x62-jrwf (CVE-2026-42033), severity high
    What it is: Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-pf86-5x62-jrwf
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 5, 2026

    Axios: Header Injection via Prototype Pollution

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-6chq-wfr3-2hj9CVE-2026-42035
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-6chq-wfr3-2hj9 (CVE-2026-42035), severity high
    What it is: Axios: Header Injection via Prototype Pollution
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-6chq-wfr3-2hj9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-xx6v-rp6x-q39cCVE-2026-42042
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-xx6v-rp6x-q39c (CVE-2026-42042), severity medium
    What it is: Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-xx6v-rp6x-q39c
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-w9j2-pvgh-6h63CVE-2026-42041
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-w9j2-pvgh-6h63 (CVE-2026-42041), severity medium
    What it is: Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-w9j2-pvgh-6h63
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 5, 2026

    Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

    • axios >= 1.0.0, < 1.15.1 · fixed in 1.15.1
    • axios <= 0.31.0 · fixed in 0.31.1
    GHSA-pmwg-cvhr-8vh7CVE-2026-42043
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-pmwg-cvhr-8vh7 (CVE-2026-42043), severity high
    What it is: Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.1. Fixed in 1.15.1.
    - axios: affected versions <= 0.31.0. Fixed in 0.31.1.
    Details: https://github.com/advisories/GHSA-pmwg-cvhr-8vh7
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumMay 5, 2026

    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

    • axios >= 1.0.0, < 1.15.2 · fixed in 1.15.2
    GHSA-3w6x-2g7m-8v23CVE-2026-42044
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-3w6x-2g7m-8v23 (CVE-2026-42044), severity medium
    What it is: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
    Affected packages:
    - axios: affected versions >= 1.0.0, < 1.15.2. Fixed in 1.15.2.
    Details: https://github.com/advisories/GHSA-3w6x-2g7m-8v23
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.

From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.

Keeping axios patched

  • npm audit (or pnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.
  • Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
  • A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.