Axios

Axios

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.53%
  • Veröffentlicht 28.09.2026 17:10:16
  • Zuletzt bearbeitet 30.09.2026 19:38:27

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup does not consistently apply proxy settings and caller-supplied DNS lookup policy. An HTTPS request uses httpVersion: 2 with explici...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 01.09.2026 15:38:39

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with top-level keys ending in '{}'. Attackers who control object keys and nested values passed to axios fo...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 01.09.2026 15:40:58

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON() and used internally when serializing FormData with Content-Type: application/json). When an applicat...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 01.09.2026 15:40:08

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing requests to 0.0.0.0 to bypass NO_PROXY rules. Attackers can supply 0.0.0.0 URLs to route requests through c...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 01.09.2026 15:40:01

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), a...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 01.09.2026 15:39:49

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent with httpVersion: 2. Because Node's HTTP/2 request API does not honor the maxBodyLength option and axi...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 01.09.2026 15:39:26

axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component. While the top-level merged config uses a nu...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 01.08.2026 12:22:17
  • Zuletzt bearbeitet 01.09.2026 15:39:00

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immut...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 01.08.2026 12:22:16
  • Zuletzt bearbeitet 01.09.2026 15:39:55

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length cannot be determined. Attackers can supply unknown-length stream data to bypass upload size limits and ...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 01.08.2026 12:22:16
  • Zuletzt bearbeitet 01.09.2026 15:40:20

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-pollution primi...