Information on source package node-axios

Available versions

ReleaseVersion
bullseye0.21.1+dfsg-1+deb11u1
bookworm1.2.1+dfsg-1+deb12u1
trixie1.8.4+dfsg-1
forky1.19.0-1
sid1.19.0-1

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-67321vulnerablevulnerablevulnerablefixedfixedaxios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain a ...
CVE-2026-67319vulnerablevulnerablevulnerablefixedfixedaxios before 0.33.0 (and 1.x before 1.18.0) can consume inherited prop ...
CVE-2026-67317vulnerablevulnerablevulnerablefixedfixedaxios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for W ...
CVE-2026-67316vulnerablevulnerablevulnerablefixedfixedaxios is vulnerable to read-side prototype-pollution gadgets that can ...
CVE-2026-67313vulnerablevulnerablevulnerablefixedfixedaxios versions 0.28.0 and later contain uncontrolled recursion in form ...
CVE-2026-67312vulnerablevulnerablevulnerablefixedfixedaxios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 ...
CVE-2026-44496vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Axio ...
CVE-2026-44495vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. From ...
CVE-2026-44494vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. From ...
CVE-2026-44492vulnerable (no DSA, postponed)fixedvulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-44490vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-44488fixedfixedvulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Axio ...
CVE-2026-44487fixedvulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-44486fixedvulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42264vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. From ...
CVE-2026-42044vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. From ...
CVE-2026-42043vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42042vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42041vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42040vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42039vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42038vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42037vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. From ...
CVE-2026-42036vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42035vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42034vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-42033vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2026-40175vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Vers ...
CVE-2026-39865vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Star ...
CVE-2026-25639vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2025-62718vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. Prio ...
CVE-2025-58754vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)fixedfixedAxios is a promise based HTTP client for the browser and Node.js. When ...
CVE-2025-27152vulnerable (no DSA, postponed)vulnerable (no DSA)fixedfixedfixedaxios is a promise based HTTP client for the browser and node.js. The ...
CVE-2024-57965vulnerable (no DSA, postponed)fixedfixedfixedfixedIn axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a U ...
CVE-2023-45857vulnerable (no DSA)fixedfixedfixedfixedAn issue discovered in Axios 1.5.1 inadvertently reveals the confident ...

Resolved issues

BugDescription
CVE-2026-67320axios in a Node.js deployment using the HTTP adapter can route request ...
CVE-2026-67318axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the con ...
CVE-2026-67315axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to r ...
CVE-2026-67314axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-s ...
CVE-2026-44489Axios is a promise based HTTP client for the browser and Node.js. From ...
CVE-2024-39338axios 1.7.2 allows SSRF via unexpected behavior where requests for pat ...
CVE-2021-3749axios is vulnerable to Inefficient Regular Expression Complexity
CVE-2020-28168Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) ...
CVE-2019-10742Axios up to and including 0.18.0 allows attackers to cause a denial of ...

Search for package or bug name: Reporting problems