OSS Support Hub / Developer Tools

Node.js Developer Tools MIT Latest: v1.16.1

Axios

Promise-based HTTP client for the browser and Node.js with interceptors and automatic transforms

Project Health at a Glance

Live data from GitHub and npm, updated daily.

โญ
109.1K+3
GitHub Stars
๐Ÿ“ฆ
v1.16.1
Latest Release ยท 2 days ago
๐Ÿ”„
8d
Avg. Release Cadence
๐Ÿ›
154
Open Issues
๐Ÿ“…
2 days ago
Last Commit
โฌ‡๏ธ
108.6M
Weekly Downloads
๐Ÿ”’
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

Published: 2026-04-09 Fixed in: 1.15.0

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

Published: 2026-05-05 Fixed in: 1.15.2

Denial of Service in axios

Published: 2019-05-29 Fixed in: 0.18.1

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

Published: 2026-02-09 Fixed in: 1.13.5

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Published: 2026-05-05 Fixed in: 1.15.1

Axios is vulnerable to DoS attack through lack of data size check

Published: 2025-09-11 Fixed in: 1.12.0

Axios vulnerable to Server-Side Request Forgery

Published: 2021-01-04 Fixed in: 0.21.1

Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

Published: 2026-05-05 Fixed in: 1.15.1

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

Published: 2026-05-05 Fixed in: 1.15.1

Axios: Header Injection via Prototype Pollution

Published: 2026-05-05 Fixed in: 1.15.1

Alternatives to Axios

Other Developer Tools projects in the Node.js ecosystem worth evaluating.

Support Options for Axios

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Axios โ€” without relying on volunteer maintainers.

Talk to an Expert โ†’