- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
As of 09/13/2026, axios recorded 10 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, axios had the most security vulnerabilities in the axios ecosystem, with 10 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-67321axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67319axios before 0.33.0 Prototype Pollution via nested option objects | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67318axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2 | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67316axios before 1.18.0 Prototype Pollution via bodyless methods | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67315axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 | Exploitation statusNot known exploited | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67312axios 0.28.0 before 0.33.0 Denial of Service via formToJSON | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67320axios before 0.33.0 Prototype Pollution via Node HTTP adapter | Exploitation statusNot known exploited | FixYes | Affected productaxios | Published08/01/2026 | SeverityHigh |
CVE-2026-67317axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67314axios before 1.18.0 Prototype Pollution via auth subfields | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-67313axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published08/01/2026 | SeverityMedium |
CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axios | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-44490Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityMedium |
CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-44494Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-44489Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityLow |
CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718) | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published06/11/2026 | SeverityHigh |
CVE-2026-42264Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published05/08/2026 | SeverityHigh |
CVE-2026-42042Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityMedium |
CVE-2026-42039Axios: unbounded recursion in toFormData causes DoS via deeply nested request data | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityMedium |
CVE-2026-42036Axios: HTTP adapter streamed responses bypass maxContentLength | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityMedium |
CVE-2026-42034Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0 | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityMedium |
CVE-2026-42037Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityMedium |
CVE-2026-42038Axios: no_proxy bypass via IP alias allows SSRF | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityMedium |
CVE-2026-42041Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityHigh |
CVE-2026-42043Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0 | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityHigh |
CVE-2026-42044Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityHigh |
CVE-2026-42040Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityLow |
CVE-2026-42035Axios: Header Injection via Prototype Pollution | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityHigh |
CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/24/2026 | SeverityHigh |
CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/10/2026 | SeverityHigh |
CVE-2025-62718Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/09/2026 | SeverityMedium |
CVE-2026-39865Axios HTTP/2 Session Cleanup State Corruption Vulnerability | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published04/08/2026 | SeverityMedium |
CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfig | Exploitation statusNot known exploited | FixYes | Affected productaxios | Published02/09/2026 | SeverityHigh |
CVE-2025-58754Axios is vulnerable to DoS attack through lack of data size check | Exploitation statusPublic exploit | FixNot confirmed | Affected productaxios | Published09/12/2025 | SeverityHigh |
CVE-2025-27152Possible SSRF and Credential Leakage via Absolute URL in axios Requests | Exploitation statusPublic exploit | FixYes | Affected productaxios | Published03/07/2025 | SeverityHigh |
CVE-2024-57965 | Exploitation statusNot known exploited | FixYes | Affected productaxios | Published01/29/2025 | SeverityInformational |
CVE-2024-39338 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published08/09/2024 | SeverityMedium |
CVE-2023-45857 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published11/08/2023 | SeverityUnknown |
CVE-2021-3749Inefficient Regular Expression Complexity in axios/axios | Exploitation statusNot confirmed | FixNot confirmed | Affected productaxios/axios | Published08/31/2021 | SeverityHigh |
CVE-2020-28168 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published11/06/2020 | SeverityUnknown |
CVE-2019-10742 | Exploitation statusNot confirmed | FixNot confirmed | Affected productaxios | Published05/07/2019 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan