CVE-2026-42264
- EPSS 0.07%
- Veröffentlicht 08.05.2026 03:20:24
- Zuletzt bearbeitet 13.05.2026 17:53:45
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct propert...
CVE-2026-42044
- EPSS 0.13%
- Veröffentlicht 24.04.2026 18:16:31
- Zuletzt bearbeitet 27.04.2026 20:04:11
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to ...
- EPSS 0.06%
- Veröffentlicht 24.04.2026 18:16:31
- Zuletzt bearbeitet 27.04.2026 20:05:04
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass th...
CVE-2026-42042
- EPSS 0.04%
- Veröffentlicht 24.04.2026 18:16:31
- Zuletzt bearbeitet 27.04.2026 20:05:27
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config pro...
CVE-2026-42041
- EPSS 0.13%
- Veröffentlicht 24.04.2026 18:16:31
- Zuletzt bearbeitet 27.04.2026 20:07:58
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error resp...
CVE-2026-42039
- EPSS 0.07%
- Veröffentlicht 24.04.2026 18:16:30
- Zuletzt bearbeitet 27.04.2026 19:50:46
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeErr...
CVE-2026-42038
- EPSS 0.06%
- Veröffentlicht 24.04.2026 18:16:30
- Zuletzt bearbeitet 27.04.2026 19:52:16
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the pro...
CVE-2026-42037
- EPSS 0.08%
- Veröffentlicht 24.04.2026 18:16:30
- Zuletzt bearbeitet 27.04.2026 19:54:56
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part withou...
CVE-2026-42036
- EPSS 0.07%
- Veröffentlicht 24.04.2026 18:16:30
- Zuletzt bearbeitet 27.04.2026 19:57:11
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and...
CVE-2026-42034
- EPSS 0.07%
- Veröffentlicht 24.04.2026 18:16:30
- Zuletzt bearbeitet 27.04.2026 19:59:18
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent f...