Search CVE reports


Toggle filters

1 – 10 of 49 results


CVE-2026-101905

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101904

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101902

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101898

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-67321

Medium priority
Needs evaluation

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-67320

Medium priority
Needs evaluation

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-67319

Medium priority
Needs evaluation

axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-67318

Medium priority
Needs evaluation

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-67317

Medium priority
Needs evaluation

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-67316

Medium priority
Needs evaluation

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages