Search CVE reports


Toggle filters

11 – 20 of 45 results


CVE-2026-44496

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44495

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44494

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44492

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44490

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44489

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain....

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44488

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44487

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-44486

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42264

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are...

1 affected package

node-axios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-axios Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages