OSS Support Hub / Developer Tools

Node.js Developer Tools MIT Latest: v1.18.1

Axios

Promise-based HTTP client for the browser and Node.js with interceptors and automatic transforms

Project Health at a Glance

Live data from GitHub and npm, updated daily.

109.2K+133
GitHub Stars
📦
v1.18.1
Latest Release · 8 days ago
🔄
7d
Avg. Release Cadence
🐛
106
Open Issues
📅
Yesterday
Last Commit
⬇️
118.7M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Published: 2026-05-29 Fixed in: 1.16.0

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Published: 2026-05-29 Fixed in: 1.15.2

Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

Published: 2026-04-09 Fixed in: 1.15.0

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

Published: 2026-05-05 Fixed in: 1.15.2

Denial of Service in axios

Published: 2019-05-29 Fixed in: 0.18.1

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

Published: 2026-02-09 Fixed in: 1.13.5

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Published: 2026-05-05 Fixed in: 1.15.1

Axios is vulnerable to DoS attack through lack of data size check

Published: 2025-09-11 Fixed in: 1.12.0

Axios vulnerable to Server-Side Request Forgery

Published: 2021-01-04 Fixed in: 0.21.1

Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

Published: 2026-05-05 Fixed in: 1.15.1

Alternatives to Axios

Other Developer Tools projects in the Node.js ecosystem worth evaluating.

Support Options for Axios

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Axios — without relying on volunteer maintainers.