axios
Promise based HTTP client for the browser and node.js
Security Advisories for axios in npm
High
about 1 month ago
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
npm
axios
Moderate
about 1 month ago
Axios: Nested axios option objects can consume polluted prototype values
npm
axios
Moderate
about 1 month ago
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
npm
axios
Moderate
about 1 month ago
Axios: Prototype pollution gadgets can alter axios request construction
npm
axios
Moderate
about 1 month ago
Axios: Excessive recursion in formDataToJSON can cause denial of service
npm
axios
Moderate
about 1 month ago
Axios: Prototype pollution auth subfields can inject Basic auth
npm
axios
Moderate
about 1 month ago
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
npm
axios
High
3 months ago
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
npm
axios
High
3 months ago
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
npm
axios
High
3 months ago
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
npm
axios
High
3 months ago
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
npm
axios
Moderate
3 months ago
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
npm
axios
Moderate
4 months ago
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
npm
axios
Moderate
4 months ago
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
npm
axios
Moderate
4 months ago
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
npm
axios
High
4 months ago
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
npm
axios
Moderate
4 months ago
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
npm
axios
Moderate
4 months ago
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
npm
axios
Moderate
4 months ago
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
npm
axios
Moderate
5 months ago
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
npm
axios
Moderate
5 months ago
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
npm
axios
High
7 months ago
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
npm
axios
High
over 1 year ago
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
npm
axios