Promise based HTTP client for the browser and node.js
92%
Total Score
63
100
100
95
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-44495 New axios is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 1.0.0 - 1.15.2 and 0.19.0 - 0.31.1. | 0.19.0 - 0.31.11.0.0 - 1.15.2 | High |
CVE-2026-44494 New axios is vulnerable to Unintended Proxy or Intermediary ('Confused Deputy') in versions 1.0.0 - 1.16.0. | 1.0.0 - 1.16.0 | High |
CVE-2026-44492 New axios is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.0.0 - 1.16.0 and 0.0.0 - 0.31.1. | 0.0.0 - 0.31.11.0.0 - 1.16.0 | High |
CVE-2026-44490 New axios is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 1.0.0 - 1.16.0 and 0.0.0 - 0.31.1. | 0.0.0 - 0.31.11.0.0 - 1.16.0 | Medium |
CVE-2026-44489 New axios is vulnerable to Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in versions 1.15.2 - 1.15.2. | 1.15.2 - 1.15.2 | Low |
| Dependency | Last Release | Score |
|---|---|---|
form-data Version ^4.0.5 | — | — |
proxy-from-env Version ^2.1.0 | — | — |
follow-redirects Version ^1.16.0 | — | — |
https-proxy-agent Version ^5.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant