← Back

Axios

axios

Vendor: Axios • 44 CVEs

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Axios
1Axios
Jun 17, 2026
Nov 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensiti...Show more
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.Show less
3Axios
OracleSiemens
3Axios
GoldengateSinec Ins
Jun 17, 2026
Aug 31, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
axios is vulnerable to Inefficient Regular Expression Complexity
2Axios
Siemens
2Axios
Sinec Ins
Jun 17, 2026
Nov 6, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.
1Axios
1Axios
Jun 17, 2026
May 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.