axios
27 known vulnerabilities affecting axios products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-62718 | High | 1.2% | 9.9 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.… | |
| CVE-2026-25639 | Medium | 2.8% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to versi… | |
| CVE-2026-44494 | Medium | 1.0% | 8.7 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to … | |
| CVE-2026-44492 | Medium | 0.9% | 8.6 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.… | |
| CVE-2026-42033 | Medium | 0.8% | 7.4 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.… | |
| CVE-2026-44495 | Medium | 0.8% | 7.0 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to… | |
| CVE-2026-42039 | Medium | 0.7% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.… | |
| CVE-2026-42264 | Medium | 0.7% | 7.4 | Axios is a promise based HTTP client for the browser and Node.js. From version 1… | |
| CVE-2026-44496 | Medium | 0.7% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions… | |
| CVE-2026-44487 | Medium | 0.7% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.… | |
| CVE-2026-44486 | Medium | 0.7% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.… | |
| CVE-2026-44488 | Medium | 0.7% | 7.5 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions… | |
| CVE-2026-42043 | Medium | 0.7% | 7.2 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.… | |
| CVE-2026-67317 | Medium | 0.5% | 7.5 | axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG Read… | |
| CVE-2026-67312 | Medium | 0.4% | 7.5 | axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain un… | |
| CVE-2026-67313 | Medium | 0.4% | 7.5 | axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON… | |
| CVE-2026-67320 | Medium | 0.4% | 7.5 | axios in a Node.js deployment using the HTTP adapter can route requests through … | |
| CVE-2026-67321 | Medium | 0.4% | 7.5 | axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomple… | |
| CVE-2026-67316 | Medium | 0.4% | 7.4 | axios is vulnerable to read-side prototype-pollution gadgets that can alter requ… | |
| CVE-2026-67315 | Medium | 0.3% | 7.5 | axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0… | |
| CVE-2026-40175 | Low | 1.9% | 4.8 | Axios is a promise based HTTP client for the browser and Node.js. Versions prior… | |
| CVE-2026-39865 | Low | 0.7% | 5.9 | Axios is a promise based HTTP client for the browser and Node.js. Starting in ve… | |
| CVE-2026-42041 | Low | 0.6% | 4.8 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.… | |
| CVE-2026-42044 | Low | 0.6% | 6.5 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to … | |
| CVE-2026-67318 | Low | 0.4% | 5.3 | axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured ma… | |
| CVE-2026-67314 | Low | 0.4% | 6.5 | axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadget… | |
| CVE-2026-67319 | Low | 0.2% | 3.7 | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties fro… |