{"schema_version":1,"title":"Axios vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 75 vulnerabilities in Axios: 0 in the last 7 days and 38 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, Axios nested option objects prototype pollution gadget, was published on 1 August 2026.","url":"https://junglewise.ai/threats/technologies/axios","json_url":"https://junglewise.ai/threats/technologies/axios.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/axios","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":27,"all_time":75,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":38,"last_365_days":67},"latest":[{"cvss":3.7,"slug":"axios-nested-option-objects-prototype-pollution-gadget-b2852cf7","title":"Axios nested option objects prototype pollution gadget","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/axios-nested-option-objects-prototype-pollution-gadget-b2852cf7"},{"cvss":7.5,"slug":"axios-node-http-adapter-proxy-injection-via-prototype-pollution-ce5dbbad","title":"Axios Node HTTP adapter proxy injection via prototype pollution","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/axios-node-http-adapter-proxy-injection-via-prototype-pollution-ce5dbbad"},{"cvss":3.1,"slug":"axios-node-http-adapter-proxy-inheritance-via-interceptor-config-2c3ad1d8","title":"Axios Node HTTP adapter proxy inheritance via interceptor config cloning","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/axios-node-http-adapter-proxy-inheritance-via-interceptor-config-2c3ad1d8"},{"cvss":7.5,"slug":"axios-form-serializer-maxdepth-bypass-via-metatoken-a3285ce5","title":"Axios form serializer maxDepth bypass via {} metatoken","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/axios-form-serializer-maxdepth-bypass-via-metatoken-a3285ce5"},{"cvss":3.1,"slug":"axios-form-serializer-maxdepth-bypass-via-metatoken-e443b5bd","title":"Axios form serializer maxDepth bypass via {} metatoken","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/axios-form-serializer-maxdepth-bypass-via-metatoken-e443b5bd"},{"cvss":3.1,"slug":"axios-prototype-pollution-in-nested-option-objects-a4c7e802","title":"Axios prototype pollution in nested option objects","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:28+00:00","url":"https://junglewise.ai/threats/axios-prototype-pollution-in-nested-option-objects-a4c7e802"},{"cvss":7.5,"slug":"axios-excessive-recursion-in-formdatatojson-denial-of-service-3c93895e","title":"Axios excessive recursion in formDataToJSON denial of service","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-excessive-recursion-in-formdatatojson-denial-of-service-3c93895e"},{"cvss":7.5,"slug":"axios-no-proxy-bypass-for-0-0-0-0-local-addresses-1c64658e","title":"Axios NO_PROXY bypass for 0.0.0.0 local addresses","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-no-proxy-bypass-for-0-0-0-0-local-addresses-1c64658e"},{"cvss":6.3,"slug":"axios-uncontrolled-recursion-in-formdatatojson-denial-of-service-99f685fa","title":"Axios uncontrolled recursion in formDataToJSON denial of service","severity":"medium","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-uncontrolled-recursion-in-formdatatojson-denial-of-service-99f685fa"},{"cvss":3.1,"slug":"axios-fetch-adapter-readablestream-maxbodylength-bypass-cf80b452","title":"Axios fetch adapter ReadableStream maxBodyLength bypass","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-fetch-adapter-readablestream-maxbodylength-bypass-cf80b452"},{"cvss":7.5,"slug":"axios-fetch-adapter-readablestream-uploads-bypass-maxbodylength-91701c14","title":"Axios fetch adapter ReadableStream uploads bypass maxBodyLength","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-fetch-adapter-readablestream-uploads-bypass-maxbodylength-91701c14"},{"cvss":4,"slug":"axios-deep-formtojson-key-recursion-denial-of-service-104a2b4d","title":"Axios Deep formToJSON Key Recursion Denial of Service","severity":"medium","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-deep-formtojson-key-recursion-denial-of-service-104a2b4d"},{"cvss":3.1,"slug":"axios-http-2-streamed-uploads-bypass-maxbodylength-a036205e","title":"Axios HTTP/2 streamed uploads bypass maxBodyLength","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-http-2-streamed-uploads-bypass-maxbodylength-a036205e"},{"cvss":3.1,"slug":"axios-no-proxy-bypass-via-0-0-0-0-local-address-1fdb98ae","title":"Axios NO_PROXY bypass via 0.0.0.0 local address","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-no-proxy-bypass-via-0-0-0-0-local-address-1fdb98ae"},{"cvss":6.3,"slug":"axios-prototype-pollution-in-basic-auth-subfield-handling-84a58e9b","title":"Axios prototype pollution in Basic auth subfield handling","severity":"medium","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-prototype-pollution-in-basic-auth-subfield-handling-84a58e9b"},{"cvss":3.1,"slug":"axios-excessive-recursion-in-formdatatojson-denial-of-service-f53cc442","title":"Axios excessive recursion in formDataToJSON denial of service","severity":"low","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-excessive-recursion-in-formdatatojson-denial-of-service-f53cc442"},{"cvss":5.3,"slug":"axios-http-2-streamed-uploads-bypass-maxbodylength-4f7ce9e1","title":"Axios HTTP/2 streamed uploads bypass maxBodyLength","severity":"medium","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-http-2-streamed-uploads-bypass-maxbodylength-4f7ce9e1"},{"cvss":4,"slug":"axios-prototype-pollution-in-request-construction-6e0ba22f","title":"axios Prototype pollution in request construction","severity":"medium","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/axios-prototype-pollution-in-request-construction-6e0ba22f"},{"cve":"CVE-2026-67321","cvss":7.5,"epss":0.0053,"slug":"cve-2026-67321-axios-form-serializer-maxdepth-bypass-via-metatoken","title":"axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing obje","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:02.36+00:00","url":"https://junglewise.ai/threats/cve-2026-67321-axios-form-serializer-maxdepth-bypass-via-metatoken"},{"cve":"CVE-2026-67320","cvss":7.5,"epss":0.0052,"slug":"cve-2026-67320-axios-node-http-adapter-proxy-inheritance-via-interceptor-cloning","title":"axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request c","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:02.217+00:00","url":"https://junglewise.ai/threats/cve-2026-67320-axios-node-http-adapter-proxy-inheritance-via-interceptor-cloning"},{"cve":"CVE-2026-67319","cvss":4,"epss":0.0032,"slug":"cve-2026-67319-axios-prototype-pollution-via-nested-option-objects","title":"axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process'","severity":"medium","exploited":false,"published_at":"2026-08-01T13:17:02.08+00:00","url":"https://junglewise.ai/threats/cve-2026-67319-axios-prototype-pollution-via-nested-option-objects"},{"cve":"CVE-2026-67318","cvss":5.3,"epss":0.0062,"slug":"cve-2026-67318-axios-http-2-streamed-uploads-bypass-maxbodylength","title":"axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests a","severity":"medium","exploited":false,"published_at":"2026-08-01T13:17:01.947+00:00","url":"https://junglewise.ai/threats/cve-2026-67318-axios-http-2-streamed-uploads-bypass-maxbodylength"},{"cve":"CVE-2026-67317","cvss":7.5,"epss":0.006,"slug":"cve-2026-67317-axios-fetch-adapter-readablestream-uploads-bypass-maxbodylength","title":"axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:01.817+00:00","url":"https://junglewise.ai/threats/cve-2026-67317-axios-fetch-adapter-readablestream-uploads-bypass-maxbodylength"},{"cve":"CVE-2026-67316","cvss":7.4,"epss":0.0042,"slug":"cve-2026-67316-axios-prototype-pollution-gadgets-in-request-construction","title":"axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been poll","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-67316-axios-prototype-pollution-gadgets-in-request-construction"},{"cve":"CVE-2026-67315","cvss":7.5,"epss":0.0046,"slug":"cve-2026-67315-axios-no-proxy-bypass-via-0-0-0-0-address","title":"axios NO_PROXY bypass via 0.0.0.0 address","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:01.54+00:00","url":"https://junglewise.ai/threats/cve-2026-67315-axios-no-proxy-bypass-via-0-0-0-0-address"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":28},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Axios","slug":"axios","vendor":{"name":"Axios","slug":"axios","url":"https://junglewise.ai/threats/vendors/axios"},"aliases":[],"category":"library","homepage":"https://axios-http.com/","repo_url":"https://github.com/axios/axios","description":"JavaScript HTTP client library for making requests from browsers and Node.js.","url":"https://junglewise.ai/threats/technologies/axios"},"most_severe":[{"cve":"CVE-2025-62718","cvss":9.9,"epss":0.0119,"slug":"cve-2025-62718-axios-hostname-normalization-proxy-bypass-and-ssrf","title":"Axios hostname normalization proxy bypass and SSRF","severity":"critical","exploited":false,"published_at":"2026-04-09T15:16:08.65+00:00","url":"https://junglewise.ai/threats/cve-2025-62718-axios-hostname-normalization-proxy-bypass-and-ssrf"},{"cve":"CVE-2026-44494","cvss":8.7,"epss":0.0093,"slug":"cve-2026-44494-axios-prototype-pollution-gadget-in-node-proxy-handling","title":"Axios Prototype Pollution Gadget in Node Proxy Handling","severity":"high","exploited":false,"published_at":"2026-06-11T17:16:33.313+00:00","url":"https://junglewise.ai/threats/cve-2026-44494-axios-prototype-pollution-gadget-in-node-proxy-handling"},{"cve":"CVE-2026-44492","cvss":8.6,"epss":0.0078,"slug":"cve-2026-44492-axios-ssrf-via-ipv4-mapped-ipv6-no-proxy-bypass","title":"Axios SSRF via IPv4-mapped IPv6 NO_PROXY bypass","severity":"high","exploited":false,"published_at":"2026-06-11T17:16:33.167+00:00","url":"https://junglewise.ai/threats/cve-2026-44492-axios-ssrf-via-ipv4-mapped-ipv6-no-proxy-bypass"},{"cve":"CVE-2026-25639","cvss":7.5,"epss":0.0177,"slug":"cve-2026-25639-axios-denial-of-service-in-mergeconfig","title":"Axios denial of service in mergeConfig","severity":"high","exploited":false,"published_at":"2026-02-09T21:15:49.01+00:00","url":"https://junglewise.ai/threats/cve-2026-25639-axios-denial-of-service-in-mergeconfig"},{"cve":"CVE-2026-44496","cvss":7.5,"epss":0.0097,"slug":"cve-2026-44496-axios-redos-via-unsanitized-xsrf-cookie-name","title":"Axios ReDoS via unsanitized XSRF cookie name","severity":"high","exploited":false,"published_at":"2026-06-11T17:16:33.59+00:00","url":"https://junglewise.ai/threats/cve-2026-44496-axios-redos-via-unsanitized-xsrf-cookie-name"},{"cve":"CVE-2026-42039","cvss":7.5,"epss":0.0097,"slug":"cve-2026-42039-axios-unbounded-recursion-denial-of-service-in-toformdata","title":"Axios unbounded recursion denial of service in toFormData","severity":"high","exploited":false,"published_at":"2026-04-24T18:16:30.827+00:00","url":"https://junglewise.ai/threats/cve-2026-42039-axios-unbounded-recursion-denial-of-service-in-toformdata"},{"cve":"CVE-2026-44488","cvss":7.5,"epss":0.0093,"slug":"cve-2026-44488-axios-resource-exhaustion-via-size-limit-bypass-in-fetch-adapter","title":"Axios resource exhaustion via size limit bypass in fetch adapter","severity":"high","exploited":false,"published_at":"2026-06-11T17:16:32.75+00:00","url":"https://junglewise.ai/threats/cve-2026-44488-axios-resource-exhaustion-via-size-limit-bypass-in-fetch-adapter"},{"cve":"CVE-2026-40895","cvss":7.5,"epss":0.0082,"slug":"cve-2026-40895-follow-redirects-sensitive-header-leak-in-cross-domain-redirects","title":"follow-redirects sensitive header leak in cross-domain redirects","severity":"high","exploited":false,"published_at":"2026-04-21T21:16:44.337+00:00","url":"https://junglewise.ai/threats/cve-2026-40895-follow-redirects-sensitive-header-leak-in-cross-domain-redirects"},{"cve":"CVE-2026-44486","cvss":7.5,"epss":0.0076,"slug":"cve-2026-44486-axios-information-exposure-via-proxy-authorization-header-leak","title":"Axios information exposure via Proxy-Authorization header leak","severity":"high","exploited":false,"published_at":"2026-06-11T17:16:32.45+00:00","url":"https://junglewise.ai/threats/cve-2026-44486-axios-information-exposure-via-proxy-authorization-header-leak"},{"cve":"CVE-2026-67317","cvss":7.5,"epss":0.006,"slug":"cve-2026-67317-axios-fetch-adapter-readablestream-uploads-bypass-maxbodylength","title":"axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content","severity":"high","exploited":false,"published_at":"2026-08-01T13:17:01.817+00:00","url":"https://junglewise.ai/threats/cve-2026-67317-axios-fetch-adapter-readablestream-uploads-bypass-maxbodylength"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}