| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|
| CVE-2026-67321 | vulnerable | vulnerable | vulnerable | fixed | fixed | axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ... |
| CVE-2026-67319 | vulnerable | vulnerable | vulnerable | fixed | fixed | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited prop ... |
| CVE-2026-67317 | vulnerable | vulnerable | vulnerable | fixed | fixed | axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for W ... |
| CVE-2026-67316 | vulnerable | vulnerable | vulnerable | fixed | fixed | axios is vulnerable to read-side prototype-pollution gadgets that can ... |
| CVE-2026-67313 | vulnerable | vulnerable | vulnerable | fixed | fixed | axios versions 0.28.0 and later contain uncontrolled recursion in form ... |
| CVE-2026-67312 | vulnerable | vulnerable | vulnerable | fixed | fixed | axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 ... |
| CVE-2026-44496 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Axio ... |
| CVE-2026-44495 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. From ... |
| CVE-2026-44494 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. From ... |
| CVE-2026-44492 | vulnerable (no DSA, postponed) | fixed | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-44490 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-44488 | fixed | fixed | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Axio ... |
| CVE-2026-44487 | fixed | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-44486 | fixed | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42264 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. From ... |
| CVE-2026-42044 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. From ... |
| CVE-2026-42043 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42042 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42041 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42040 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42039 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42038 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42037 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. From ... |
| CVE-2026-42036 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42035 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42034 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-42033 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2026-40175 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Vers ... |
| CVE-2026-39865 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Star ... |
| CVE-2026-25639 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2025-62718 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. Prio ... |
| CVE-2025-58754 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | Axios is a promise based HTTP client for the browser and Node.js. When ... |
| CVE-2025-27152 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | fixed | axios is a promise based HTTP client for the browser and node.js. The ... |
| CVE-2024-57965 | vulnerable (no DSA, postponed) | fixed | fixed | fixed | fixed | In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a U ... |
| CVE-2023-45857 | vulnerable (no DSA) | fixed | fixed | fixed | fixed | An issue discovered in Axios 1.5.1 inadvertently reveals the confident ... |