Promise based HTTP client for the browser and node.js
87%
Total Score
100
89
100
56
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-67319 axios is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.8.0 - 0.33.0 and 1.0.0 - 1.18.0. | 0.8.0 - 0.33.01.0.0 - 1.18.0 | Medium |
CVE-2026-67316 axios is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 1.0.0 - 1.18.0 and 0.0.0 - 0.33.0. | 0.0.0 - 0.33.01.0.0 - 1.18.0 | Medium |
CVE-2026-67315 axios is vulnerable to Permissive List of Allowed Inputs in versions 1.15.0 - 1.18.0 and 0.31.0 - 0.33.0. | 0.31.0 - 0.33.01.15.0 - 1.18.0 | Medium |
CVE-2026-67320 axios is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.31.1 - 0.33.0 and 1.15.2 - 1.18.0. | 0.31.1 - 0.33.01.15.2 - 1.18.0 | High |
CVE-2026-67318 axios is vulnerable to Uncontrolled Resource Consumption in versions 1.13.0 - 1.18.0. | 1.13.0 - 1.18.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
form-data Version ^4.0.6 | — | — |
proxy-from-env Version ^2.1.0 | — | — |
follow-redirects Version ^1.16.0 | — | — |
https-proxy-agent Version ^5.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant