axios
NPM Package
Vulnerability Check
Promise based HTTP client for the browser and node.js
axios
Advisory Breakdown
Severity Rating
High severity34 advisories
High severity
Weekly downloads
120,325,703
Total advisories
34
Latest version
1.18.0
License
MIT
Known advisories
OSV records for the npm ecosystem
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Denial of Service in axios
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Axios is vulnerable to DoS attack through lack of data size check
Axios vulnerable to Server-Side Request Forgery
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Axios: Header Injection via Prototype Pollution
Allocation of Resources Without Limits or Throttling in Axios
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
Server-Side Request Forgery in axios
axios Inefficient Regular Expression Complexity vulnerability
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
Axios: no_proxy bypass via IP alias allows SSRF
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
Axios: HTTP adapter streamed responses bypass maxContentLength
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Axios Cross-Site Request Forgery Vulnerability
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Malicious code in axios (npm)
Checked Jun 15, 2026, 11:25 AM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- axios
- Ecosystem
- npm
- Latest version
- 1.18.0
- License
- MIT
- Weekly downloads
- 120,325,703
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/15/2026, 11:25:06 AM