axios
npm55 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting axiospage 2 of 2
- CVE-2026-67317HIGHCVSS 7.5EG 7.5fixed in 1.18.02026-08-01
axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size …
- CVE-2026-67318MEDIUMCVSS 5.3EG 5.3fixed in 1.18.02026-08-01
axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength opt…
- CVE-2026-67319LOWCVSS 3.7EG 3.7fixed in 0.33.0 or 1.18.0, by version range2026-08-01
axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged confi…
- CVE-2026-67320HIGHCVSS 7.5EG 7.5fixed in 0.33.0 or 1.18.0, by version range2026-08-01
axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a c…
- CVE-2026-67321HIGHCVSS 7.5EG 7.5fixed in 0.33.0 or 1.18.0, by version range2026-08-01
axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed …
Check whether axios is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for axios CVEs against the assets you own.
Book a Demo →