An open index of dependabot pull requests across open source projects.

axios

Ecosystem:
npm
Package URL:
pkg:npm/axios
Total PRs:
70,356 Dependabot PRs
Latest PR:
about 2 hours ago
Unique Repositories:
38,525 repositories
Unique Repos (30 days):
1,918 repositories
Security Advisories
axios Inefficient Regular Expression Complexity vulnerability
GHSA-cph5-m8f7-6c5x CVE-2021-3749 HIGH published over 4 years ago • updated 11 days ago
axios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
GHSA-62hf-57xw-28j9 CVE-2026-42039 MODERATE published 25 days ago • updated 1 day ago
### Summary toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js pr...
Axios: HTTP adapter streamed responses bypass maxContentLength
GHSA-vf2m-468p-8v99 CVE-2026-42036 MODERATE published 25 days ago • updated 1 day ago
### Summary When responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured re...
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
GHSA-3g43-6gmg-66jw CVE-2026-44495 HIGH published about 12 hours ago • updated about 10 hours ago
## Summary Axios versions before the fixed releases contain prototype-pollution gadgets in request config processing. If another vulnerability in ...
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
GHSA-35jp-ww65-95wh CVE-2026-44494 HIGH published about 12 hours ago • updated about 10 hours ago
# Vulnerability Disclosure: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` ## Summary The Axios library is vulnerable to...
Recent PRs
Bump axios from 1.4.0 to 1.16.0

SQUAD-1/FC-Services #198

1.4.0 → 1.16.0 Minor PR
Open about 3 hours ago 1 comment
SQUAD-1
Bump axios from 0.19.0 to 0.32.0

joelhooks/link-loader #5

0.19.0 → 0.32.0 Minor PR
Open about 3 hours ago 1 comment
joelhooks
Bump axios from 1.6.7 to 1.16.0

qcjxs-hn/naichd #23

1.6.7 → 1.16.0 Minor PR
Open about 4 hours ago 1 comment
qcjxs-hn
Bump axios from 1.6.7 to 1.16.0

penandcode/markiyo #2

1.6.7 → 1.16.0 Minor PR
Open about 4 hours ago 1 comment
penandcode
build(deps): bump axios from 1.15.2 to 1.16.0

iomete/iom-docs #441

1.15.2 → 1.16.0 Minor PR
Open about 12 hours ago 2 comments
iomete
Package Details
Name: axios
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/axios
JSON API: View JSON
Security Advisories

29

Active advisories
HIGH 13
MODERATE 14
LOW 2
View All npm Advisories
Package Information
Description:

Promise based HTTP client for the browser and node.js

Repository: https://github.com/axios/axios
Homepage: https://axios-http.com
Latest Release: 1.9.0
about 1 year ago
Dependent Repos: 453,457
Dependent Packages: 97,210
Downloads: 273,533,655
Ranking: Top 0.0542% by dependent repos Top 0.0039% by downloads Top 0.0009% by dependent pkgs
PR Status
Open 35,948 (51.1%)
Merged 7,938 (11.3%)
Closed 24,786 (35.2%)
PR Types
Major 7,502 (10.7%)
Minor 53,160 (75.6%)
Patch 5,734 (8.1%)
Removal 2,161 (3.1%)