VYPR

npm package

axios

pkg:npm/axios

Malware

2 malicious versions on record

One or more versions of this package have been flagged as containing malicious code. Audit any system that installed an affected version.

Vulnerabilities (40)

  • CVE-2026-101899Sep 30, 2026
    affected >= 1.15.0, < 1.20.0fixed 1.20.0

    ## Summary Axios supports proxy environment variables and evaluates `NO_PROXY` exclusions in the Node.js adapter. CIDR-form `NO_PROXY` entries such as `127.0.0.0/8`, `10.0.0.0/8`, or `169.254.169.254/32` are not interpreted as IP ranges. As a result, a request to an IP address i

  • CVE-2026-101909HigSep 28, 2026
    affected >= 0.28.0, < 0.34.0fixed 0.34.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw s

  • CVE-2026-101908MedSep 28, 2026
    affected >= 1.7.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.

  • CVE-2026-101907HigSep 28, 2026
    affected >= 1.17.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and receives a redirect response. The underlying fetch

  • CVE-2026-101906HigSep 28, 2026
    affected >= 1.15.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is configured, NO_PROXY or no_proxy is non-empty, redirects are

  • CVE-2026-101905HigSep 28, 2026
    affected >= 1.15.2, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.p

  • CVE-2026-101904MedSep 28, 2026
    affected >= 1.0.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.h

  • CVE-2026-101903HigSep 28, 2026
    affected >= 1.16.1, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an attacker-controlled malformed data URL containing many slash cha

  • CVE-2026-101902MedSep 28, 2026
    affected >= 0.27.2, < 0.34.0fixed 0.34.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Obje

  • CVE-2026-101901HigSep 28, 2026
    affected >= 1.13.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A request uses httpVersion: 2 and the ClientHttp2Sessio

  • CVE-2026-101900MedSep 28, 2026
    affected >= 1.12.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or

  • CVE-2026-101898HigSep 28, 2026
    affected >= 1.13.0, < 1.20.0fixed 1.20.0

    Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explicit config.proxy or environment-

  • CVE-2026-67321HigAug 1, 2026
    affected >= 0.31.1, < 0.33.0fixed 0.33.0

    axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios form or parameter serialization

  • CVE-2026-44496HigJun 11, 2026
    affected >= 1.0.0, < 1.16.0fixed 1.16.0

    Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments

  • CVE-2026-44488HigJun 11, 2026
    affected >= 1.7.0, < 1.16.0fixed 1.16.0

    Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments wh

  • CVE-2026-44487HigJun 11, 2026
    affected >= 1.0.0, < 1.16.0fixed 1.16.0

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial

  • CVE-2026-44486HigJun 11, 2026
    affected >= 1.0.0, < 1.16.0fixed 1.16.0

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorizati

  • CVE-2026-42264HigMay 8, 2026
    affected >= 1.0.0, < 1.15.2fixed 1.15.2

    Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnPropert

  • CVE-2026-42044MedApr 24, 2026
    affected >= 1.0.0, < 1.15.2fixed 1.15.2

    Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, in

  • CVE-2026-42043HigApr 24, 2026
    affected >= 1.0.0, < 1.15.1fixed 1.15.1

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vu

Page 1 of 2