vciy

CVEs we hold for Axios

Records whose assigning authority named Axios as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-67321axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypassaxios
CVE-2026-67320axios before 0.33.0 Prototype Pollution via Node HTTP adapteraxios
CVE-2026-67319axios before 0.33.0 Prototype Pollution via nested option objectsaxios
CVE-2026-67318axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2axios
CVE-2026-67317axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStreamaxios
CVE-2026-67316axios before 1.18.0 Prototype Pollution via bodyless methodsaxios
CVE-2026-67315axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0axios
CVE-2026-67314axios before 1.18.0 Prototype Pollution via auth subfieldsaxios
CVE-2026-67313axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSONaxios
CVE-2026-67312axios 0.28.0 before 0.33.0 Denial of Service via formToJSONaxios
CVE-2026-44496Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injectionaxios
CVE-2026-44495Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Mergeaxios
CVE-2026-44494Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`axios
CVE-2026-44492Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for…axios
CVE-2026-44490Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functionsaxios
CVE-2026-44489Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fixaxios
CVE-2026-44488Axios: Allocation of Resources Without Limits or Throttling in axiosaxios
CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapteraxios
CVE-2026-44486Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionaxios
CVE-2026-42264Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijackingaxios
CVE-2026-42044Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`axios
CVE-2026-42043Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in…axios
CVE-2026-42042Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercionaxios
CVE-2026-42041Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategyaxios
CVE-2026-42040Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParamsaxios
CVE-2026-42039Axios: unbounded recursion in toFormData causes DoS via deeply nested request dataaxios
CVE-2026-42038Axios: no_proxy bypass via IP alias allows SSRFaxios
CVE-2026-42037Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStreamaxios
CVE-2026-42036Axios: HTTP adapter streamed responses bypass maxContentLengthaxios
CVE-2026-42035Axios: Header Injection via Prototype Pollutionaxios
CVE-2026-42034Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0axios
CVE-2026-42033Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijackingaxios
CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chainaxios
CVE-2026-39865Axios HTTP/2 Session Cleanup State Corruption Vulnerabilityaxios
CVE-2026-25639Axios affected by Denial of Service via __proto__ Key in mergeConfigaxios
CVE-2025-62718Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFaxios
CVE-2025-58754Axios is vulnerable to DoS attack through lack of data size checkaxios
CVE-2025-27152Possible SSRF and Credential Leakage via Absolute URL in axios Requestsaxios
CVE-2024-57965no title heldaxios
CVE-2021-3749Inefficient Regular Expression Complexity in axios/axiosaxios/axios
CVE-2019-25069Axios Italia Axios RE Error Message ASP.NET information disclosureAxios RE
CVE-2019-25068Axios Italia Axios RE Connection REDefault.aspx privileges managementAxios RE
CVE-2019-10742no title heldaxios

43 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.