Search CVE reports


Toggle filters

31 – 40 of 45 results


CVE-2026-42034

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path)....

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42033

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40175

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-62718

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost....

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-39865

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-25639

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-58754

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP....

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-27152

Medium priority
Needs evaluation

axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-57965

Medium priority
Needs evaluation

In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Not affected Needs evaluation Needs evaluation Ignored
Show less packages

CVE-2024-39338

Medium priority
Needs evaluation

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages