Axios is a widely embedded HTTP client library for JavaScript and Node.js that underpins request handling in a vast range of server-side applications and frameworks, giving its vulnerabilities propagation potential far exceeding its narrow product footprint. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and recur through weakness classes including prototype pollution, server-side request forgery, resource-consumption issues, and HTTP header injection that reflect the attack surface inherent to a network request handler positioned at the boundary between application logic and untrusted input. The concentration of serious flaws in a single, supply-chain-critical component means that a single disclosed vulnerability can affect thousands of downstream applications and services, making timely remediation and downstream dependency tracking essential for defenders. Organizations should maintain visibility into which applications and frameworks depend on this library and prioritize patching cycles accordingly; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Axios over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42043CRITICAL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address i | Apr 24, 2026 | 10.0 | 43 | NO | NO |
CVE-2025-62718CRITICAL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. R | Apr 9, 2026 | 9.9 | 41 | NO | NO |
CVE-2026-42264CRITICAL Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, a | May 8, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-42044CRITICAL Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows a | Apr 24, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-44494HIGH Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows | Jun 11, 2026 | 8.7 | 38 | NO | NO |
CVE-2026-44492HIGH Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 addre | Jun 11, 2026 | 8.6 | 37 | NO | NO |
CVE-2026-42039HIGH Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested va | Apr 24, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-42033HIGH Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios read | Apr 24, 2026 | 7.4 | 35 | NO | NO |
CVE-2026-44486HIGH Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affecte | Jun 11, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-44487HIGH Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected | Jun 11, 2026 | 7.5 | 34 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Axios.
Media articles that mention a CVE ID that affects a product developed by Axios — matched by CVE ID, not by vendor name.