Technology · Axios
Axios vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 75 vulnerabilities in Axios: 0 in the last 7 days and 38 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, Axios nested option objects prototype pollution gadget, was published on 1 August 2026.
- Last 7 days
- 0
- Last 90 days
- 38
- Critical, all time
- 1
- Exploited in the wild
- 0
About Axios
JavaScript HTTP client library for making requests from browsers and Node.js.
Latest Axios vulnerabilities
- Axios nested option objects prototype pollution gadgetlowCVSS 3.7
- Axios Node HTTP adapter proxy injection via prototype pollutionhighCVSS 7.5
- Axios Node HTTP adapter proxy inheritance via interceptor config cloninglowCVSS 3.1
- Axios form serializer maxDepth bypass via {} metatokenhighCVSS 7.5
- Axios form serializer maxDepth bypass via {} metatokenlowCVSS 3.1
- Axios prototype pollution in nested option objectslowCVSS 3.1
- Axios excessive recursion in formDataToJSON denial of servicehighCVSS 7.5
- Axios NO_PROXY bypass for 0.0.0.0 local addresseshighCVSS 7.5
- Axios uncontrolled recursion in formDataToJSON denial of servicemediumCVSS 6.3
- Axios fetch adapter ReadableStream maxBodyLength bypasslowCVSS 3.1
- Axios fetch adapter ReadableStream uploads bypass maxBodyLengthhighCVSS 7.5
- Axios Deep formToJSON Key Recursion Denial of ServicemediumCVSS 4
- Axios HTTP/2 streamed uploads bypass maxBodyLengthlowCVSS 3.1
- Axios NO_PROXY bypass via 0.0.0.0 local addresslowCVSS 3.1
- Axios prototype pollution in Basic auth subfield handlingmediumCVSS 6.3
- Axios excessive recursion in formDataToJSON denial of servicelowCVSS 3.1
- Axios HTTP/2 streamed uploads bypass maxBodyLengthmediumCVSS 5.3
- axios Prototype pollution in request constructionmediumCVSS 4
- CVE-2026-67321: axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js…highCVSS 7.5EPSS 0.5%
- CVE-2026-67320: axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios…highCVSS 7.5EPSS 0.5%
- CVE-2026-67319: axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the…mediumCVSS 4EPSS 0.3%
- CVE-2026-67318: axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request…mediumCVSS 5.3EPSS 0.6%
- CVE-2026-67317: axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch…highCVSS 7.5EPSS 0.6%
- CVE-2026-67316: axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has…highCVSS 7.4EPSS 0.4%
- CVE-2026-67315: axios NO_PROXY bypass via 0.0.0.0 addresshighCVSS 7.5EPSS 0.5%
Most severe Axios vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-62718: Axios hostname normalization proxy bypass and SSRFcriticalCVSS 9.9EPSS 1.2%
- CVE-2026-44494: Axios Prototype Pollution Gadget in Node Proxy HandlinghighCVSS 8.7EPSS 0.9%
- CVE-2026-44492: Axios SSRF via IPv4-mapped IPv6 NO_PROXY bypasshighCVSS 8.6EPSS 0.8%
- CVE-2026-25639: Axios denial of service in mergeConfighighCVSS 7.5EPSS 1.8%
- CVE-2026-44496: Axios ReDoS via unsanitized XSRF cookie namehighCVSS 7.5EPSS 1.0%
- CVE-2026-42039: Axios unbounded recursion denial of service in toFormDatahighCVSS 7.5EPSS 1.0%
- CVE-2026-44488: Axios resource exhaustion via size limit bypass in fetch adapterhighCVSS 7.5EPSS 0.9%
- CVE-2026-40895: follow-redirects sensitive header leak in cross-domain redirectshighCVSS 7.5EPSS 0.8%
- CVE-2026-44486: Axios information exposure via Proxy-Authorization header leakhighCVSS 7.5EPSS 0.8%
- CVE-2026-67317: axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch…highCVSS 7.5EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 10 | 0 | |
| 27 Jul 2026 | 28 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/axios.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Axios vulnerabilities", https://junglewise.ai/threats/technologies/axios, 26 September 2026.