Search CVE reports


Toggle filters

1 – 10 of 56 results


CVE-2026-101909

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution....

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101908

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101907

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the maxRedirects: 0 redirect policy. An Axios request uses the fetch adapter with maxRedirects set to zero and...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101906

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy applies a quadratic trailing-dot regular expression to redirect hostnames. HTTP_PROXY or HTTPS_PROXY is...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101905

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101904

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101903

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash characters on both sides of the media-type separator. An application passes an...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101902

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101901

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not install adequate error handling for a ClientHttp2Session during Axios HTTP/2 session initialization or reuse. A...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-101900

Medium priority
Needs evaluation

Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages