Promise based HTTP client for the browser and node.js
91%
Total Score
63
95
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-44496 axios is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.16.0 and 0.0.0 - 0.31.1. | 0.0.0 - 0.31.11.0.0 - 1.16.0 | |
CVE-2026-44488 axios is vulnerable to Allocation of Resources Without Limits or Throttling in versions 1.7.0 - 1.16.0. | 1.7.0 - 1.16.0 | |
CVE-2026-44487 axios is vulnerable to Insertion of Sensitive Information Into Sent Data in versions 1.0.0 - 1.16.0 and 0.0.0 - 0.31.1. | 0.0.0 - 0.31.11.0.0 - 1.16.0 | |
CVE-2026-44486 axios is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 1.16.0 and 0.0.0 - 0.31.1. | 0.0.0 - 0.31.11.0.0 - 1.16.0 | |
CVE-2026-44495 axios is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 1.0.0 - 1.15.2 and 0.19.0 - 0.31.1. | 0.19.0 - 0.31.11.0.0 - 1.15.2 |
| Dependency | Last Release | Score |
|---|---|---|
form-data Version ^4.0.5 | — | — |
proxy-from-env Version ^2.1.0 | — | — |
follow-redirects Version ^1.16.0 | — | — |
https-proxy-agent Version ^5.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant