LIVE · cybersecurity feed
Live wire
vendor

Axios

14 CVEs published in the last four months. Exploited flaws first.

Critical0
High14
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-444948.7highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago
CVE-2026-444928.6highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago
CVE-2026-444887.5highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago
CVE-2026-673217.5highaxiosaxios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormDat35d ago
CVE-2026-444877.5highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago
CVE-2026-673207.5highaxiosaxios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy.35d ago
CVE-2026-444867.5highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago
CVE-2026-444967.5highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago
CVE-2026-673127.5highaxiosaxios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataTo35d ago
CVE-2026-673137.5highaxiosaxios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field na35d ago
CVE-2026-673157.5highaxiosaxios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in sh35d ago
CVE-2026-673177.5highaxiosaxios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the f35d ago
CVE-2026-673167.4highaxiosaxios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.proto35d ago
CVE-2026-444957highaxiosAxios is a promise based HTTP client for the browser and Node.js.86d ago

Filter the full tracker by Axios