PatchSiren

axios CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM axios CVE published 2026-08-01

CVE-2026-67321

Axios before 0.33.0 contains an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. This vulnerability can cause a RangeError from JSON.stringify, potentially leading to denial of service in the affected request path due to excessive recursion. Developers and security teams should assess exposure and prioritize remediation based on operational impact [truncated]

HIGH axios CVE published 2026-08-01

CVE-2026-67320

Axios in Node.js deployments using the HTTP adapter is vulnerable to prototype pollution. This allows attackers to route requests through a controlled proxy, potentially disclosing sensitive information. The CVE record was published on 2026-08-01T13:17:02.217Z and has not been modified since then. Developers should review the impact of this vulnerability on their systems.

MEDIUM axios CVE published 2026-08-01

CVE-2026-67319

PatchSiren debrief for CVE-2026-67319 based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:02.080Z and has not been modified since then. This CVE describes a vulnerability in axios before 0.33.0 (and 1.x before 1.18.0) related to prototype pollution via nested option objects, which can lead to silent injection of an Authorization: Basic header and alteration of query-strin [truncated]

MEDIUM axios CVE published 2026-08-01

CVE-2026-67318

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:01.947Z and has not been modified since then. axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce maxBodyLength limit on streamed request bodies when using httpVersion: 2. This allows an attacker to cause excessive outbound data transmission, leading to resource consumption and p [truncated]

MEDIUM axios CVE published 2026-08-01

CVE-2026-67317

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:01.817Z and has not been modified since then. CVE-2026-67317 involves axios versions 1.7.0 before 1.18.0 failing to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. This allows attackers to supply unknown-length st [truncated]

MEDIUM axios CVE published 2026-08-01

CVE-2026-67315

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:01.540Z and has not been modified since then. CVE-2026-67315 is a vulnerability in axios versions 1.15.0 before 1.18.0 that allows requests to 0.0.0.0 to bypass NO_PROXY rules. This could potentially expose local services to attackers when the proxy can reach the destination. Users of axios [truncated]

MEDIUM axios CVE published 2026-08-01

CVE-2026-67314

Axios versions >=1.15.2 and <1.18.0 are vulnerable to prototype-pollution read-side gadgets in Basic auth subfield handling. This can lead to outbound request tampering when an application is already affected by a separate prototype-pollution primitive. The vulnerability allows an attacker to inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Axios users should veri [truncated]

MEDIUM axios CVE published 2026-08-01

CVE-2026-67312

Axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 are vulnerable to uncontrolled recursion in formDataToJSON. This could lead to denial-of-service attacks when an application passes attacker-controlled FormData field names. The vulnerability can cause a RangeError: Maximum call stack size exceeded, leading to process termination in applications without appropriate error handling. Affec [truncated]

HIGH axios CVE published 2026-06-11

CVE-2026-44495

Axios, a promise-based HTTP client for the browser and Node.js, contains prototype-pollution gadgets in request config processing from versions 0.19.0 to before 0.31.1 and 1.15.2. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios do [truncated]

HIGH axios CVE published 2026-06-11

CVE-2026-44494

The Axios library, a promise-based HTTP client for the browser and Node.js, is vulnerable to a Prototype Pollution 'Gadget' attack. This allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack, enabling the interception, reading, and modification of all HTTP traffic, including authentication credentials. The vulnerability exist [truncated]

HIGH axios CVE published 2026-06-11

CVE-2026-44492

Axios, a promise-based HTTP client for browser and Node.js, has a vulnerability prior to versions 0.32.0 and 1.16.0. The issue arises from Axios not normalizing IPv4-mapped IPv6 addresses. This can lead to requests being routed through a configured proxy even when the NO_PROXY list includes an IPv4 address like 127.0.0.1 or 169.254.169.254. The vulnerability allows internal services to be accessed via the [truncated]

MEDIUM axios CVE published 2026-06-11

CVE-2026-44490

Axios, a promise-based HTTP client for the browser and Node.js, is vulnerable to prototype pollution. This vulnerability, CVE-2026-44490, allows attackers to pollute the Object.prototype, potentially leading to security issues. The vulnerability exists in versions prior to 0.32.0 and 1.16.0. Axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependenc [truncated]

LOW axios CVE published 2026-06-11

CVE-2026-44489

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.username, proxy.password, and proxy.auth without hasOwnProperty checks. When Object.prototype.username is pollu [truncated]

HIGH axios CVE published 2026-06-11

CVE-2026-44488

Axios versions 1.7.0 through 1.15.x have a vulnerability where configured request and response size limits are not enforced when using the fetch adapter. This can lead to resource exhaustion in server-side usage. The vulnerability allows applications using axios with the fetch adapter to receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. [truncated]

HIGH axios CVE published 2026-06-11

CVE-2026-44487

Axios, a promise-based HTTP client for the browser and Node.js, has a vulnerability in its Node.js HTTP adapter. Prior to versions 0.32.0 and 1.16.0, Axios may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redire [truncated]

HIGH axios CVE published 2026-06-11

CVE-2026-44486

Axios, a promise-based HTTP client for Node.js, has a high-severity vulnerability (CVE-2026-44486) in its HTTP adapter that can lead to the leakage of proxy credentials to a redirect target. This issue affects Axios versions before 0.32.0 and 1.16.0 when used with Node.js and automatic redirects enabled. The vulnerability is fixed in versions 0.32.0 and 1.16.0. Defenders managing Node.js environments usin [truncated]

HIGH axios CVE published 2026-05-08

CVE-2026-42264

Axios HTTP client vulnerability allows attackers to pollute Object.prototype, potentially impacting outbound HTTP requests. Patched in version 1.15.2. The vulnerability arises from Axios reading config properties without proper guards, allowing for prototype pollution. This issue affects Axios versions from 1.0.0 to before 1.15.2. Developers and security teams should assess exposure and update to version [truncated]

HIGH axios CVE published 2026-04-24

CVE-2026-42033

Axios vulnerability allows attackers to intercept and modify JSON responses or hijack HTTP transport if Object.prototype is polluted. This occurs when a co-dependency pollutes Object.prototype, enabling attackers to silently intercept and modify every JSON response before the application sees it, or fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. Defen [truncated]

MEDIUM axios CVE published 2026-04-09

CVE-2025-62718

CVE-2025-62718 describes a proxy-bypass weakness in Axios' NO_PROXY handling. When hostname normalization is incorrect, requests aimed at loopback-style targets such as localhost. with a trailing dot or [::1] can fail to match NO_PROXY and be sent through the configured proxy instead. In environments that rely on proxy rules to keep loopback or internal traffic local, this can create SSRF-style exposure t [truncated]

HIGH axios CVE published 2026-02-09

CVE-2026-25639

Axios, a promise-based HTTP client for browser and Node.js, has a vulnerability in its mergeConfig function. This function crashes with a TypeError when configuration objects containing __proto__ as an own property are processed. An attacker can exploit this by providing a malicious configuration object created via JSON.parse(), leading to a complete denial of service. The vulnerability is fixed in versio [truncated]

HIGH axios CVE published 2022-09-13

CVE-2021-3749

CVE-2021-3749 is a HIGH severity vulnerability (CVSS 7.5) affecting Subnet Solutions Inc. PowerSYSTEM Center, published by CISA on October 1, 2024. The vulnerability stems from the product's use of Axios, a popular JavaScript HTTP client library, which contains an inefficient regular expression complexity flaw. This issue can lead to denial of service conditions through resource exhaustion when processing [truncated]