Live data from GitHub and npm, updated daily.
Data last fetched: 2026-06-29
10 active CVEs reported via OSV.dev
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Denial of Service in axios
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Axios is vulnerable to DoS attack through lack of data size check
Axios vulnerable to Server-Side Request Forgery
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
Other Developer Tools projects in the Node.js ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Axios — without relying on volunteer maintainers.