axios is vulnerable to Regular expression Denial of Service (ReDoS)
43
Medium Risk
Browser cookie reads interpolated the cookie name into a regular expression, so metacharacters in a name could distort matching or burn CPU on pathological strings. The reader now walks semicolon-separated pairs and compares the name prefix literally after trimming optional whitespace. Decoding still uses the same URI decoding helper for the value segment.
You are affected if you are using a version that falls within the vulnerable range.
axios is vulnerable to Regular expression Denial of Service (ReDoS) in versions 1.0.0 - 1.15.2.
Upgrade the axios library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant