axios

axios breaking-changes badge

axios (latest known version: 1.18.1) has 86 known breaking changes on record, each backed by a source URL.

Release cadence unknownLatest known version: 1.18.1npm ↗

Security advisories

GHSA-3w6x-2g7m-8v23MODERATE>=1.0.0 <1.15.2

Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

source ↗

GHSA-35jp-ww65-95whHIGH>=1.0.0 <1.16.0

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

source ↗

GHSA-3g43-6gmg-66jwHIGH>=1.0.0 <1.15.2 || >=0.19.0 <0.31.1

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

source ↗

GHSA-3p68-rc4w-qgx5MODERATE>=1.0.0 <1.15.0 || <0.31.0

Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

source ↗

GHSA-42h9-826w-cgv3MODERATE>=0.28.0 <0.33.0 || >=1.0.0 <1.18.0

Axios: Excessive recursion in formDataToJSON can cause denial of service

source ↗

GHSA-42xw-2xvc-qx8mHIGH<0.18.1

Denial of Service in axios

source ↗

GHSA-43fc-jf86-j433HIGH>=1.0.0 <1.13.5 || <0.30.3

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

source ↗

GHSA-445q-vr5w-6q77MODERATE>=1.0.0 <1.15.1

Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

source ↗

GHSA-4hjh-wcwx-xvwjHIGH>=1.0.0 <1.12.0 || >=0.28.0 <0.30.2

Axios is vulnerable to DoS attack through lack of data size check

source ↗

GHSA-4w2v-q235-vp99MODERATE<0.21.1

Axios vulnerable to Server-Side Request Forgery

source ↗

GHSA-5c9x-8gcm-mpgxMODERATE>=1.0.0 <1.15.1 || <0.31.1

Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

source ↗

GHSA-62hf-57xw-28j9MODERATE>=1.0.0 <1.15.1 || <0.31.1

Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

source ↗

GHSA-654m-c8p4-x5fpLOW>=1.15.2 <1.16.0

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

source ↗

GHSA-6chq-wfr3-2hj9HIGH>=1.0.0 <1.15.1 || <0.31.1

Axios: Header Injection via Prototype Pollution

source ↗

GHSA-777c-7fjr-54vfHIGH>=1.7.0 <1.16.0

Allocation of Resources Without Limits or Throttling in Axios

source ↗

GHSA-7q8q-rj6j-mhjqMODERATE>=0.8.0 <0.33.0 || >=1.0.0 <1.18.0

Axios: Nested axios option objects can consume polluted prototype values

source ↗

GHSA-898c-q2cr-xwhgMODERATE>=1.0.0 <1.16.0 || <0.32.0

axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

source ↗

GHSA-8hc4-vh64-cxmjHIGH>=1.3.2 <1.7.4

Server-Side Request Forgery in axios

source ↗

GHSA-cph5-m8f7-6c5xHIGH<0.21.2

axios Inefficient Regular Expression Complexity vulnerability

source ↗

GHSA-f4gw-2p7v-4548MODERATE>=1.15.0 <1.18.0 || >=0.31.0 <0.33.0

Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

source ↗

GHSA-fvcv-3m26-pcqxMODERATE>=1.0.0 <1.15.0 || <0.31.0

Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

source ↗

GHSA-gcfj-64vw-6mp9HIGH>=0.31.1 <0.33.0 || >=1.15.2 <1.18.0

Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

source ↗

GHSA-hcpx-6fm6-wx23MODERATE>=0.31.1 <0.33.0 || >=1.15.1 <1.18.0

Axios form serializer maxDepth bypass via {} metatoken

source ↗

GHSA-hfxv-24rg-xrqfHIGH>=1.0.0 <1.16.0 || <0.32.0

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

source ↗

GHSA-j5f8-grm9-p9fcHIGH>=1.0.0 <1.16.0 || <0.32.0

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

source ↗

GHSA-jqh4-m9w3-8hp9MODERATE>=1.7.0 <1.18.0

Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

source ↗

GHSA-jr5f-v2jv-69x6HIGH>=1.0.0 <1.8.2 || <0.30.0

axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

source ↗

GHSA-m7pr-hjqh-92cmMODERATE>=1.0.0 <1.15.1 || <0.31.1

Axios: no_proxy bypass via IP alias allows SSRF

source ↗

GHSA-mmx7-hfxf-jppxMODERATE>=1.0.0 <1.18.0 || <0.33.0

Axios: Prototype pollution gadgets can alter axios request construction

source ↗

GHSA-mwf2-3pr3-8698MODERATE>=1.13.0 <1.18.0

Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

source ↗

GHSA-p92q-9vqr-4j8vHIGH>=1.0.0 <1.16.0 || <0.32.0

Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

source ↗

GHSA-pf86-5x62-jrwfHIGH>=1.0.0 <1.15.1 || <0.31.1

Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

source ↗

GHSA-pjwm-pj3p-43mvHIGH>=1.15.0 <1.16.0 || <0.32.0

axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

source ↗

GHSA-pmv8-rq9r-6j72MODERATE>=0.28.0 <0.33.0 || >=1.0.0 <1.18.0

Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

source ↗

GHSA-pmwg-cvhr-8vh7HIGH>=1.0.0 <1.15.1 || <0.31.1

Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

source ↗

GHSA-q8qp-cvcw-x6jjHIGH>=1.0.0 <1.15.2

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

source ↗

GHSA-qj83-cq47-w5f8MODERATE>=1.13.0 <1.13.2

Axios HTTP/2 Session Cleanup State Corruption Vulnerability

source ↗

GHSA-vf2m-468p-8v99MODERATE>=1.0.0 <1.15.1 || <0.31.1

Axios: HTTP adapter streamed responses bypass maxContentLength

source ↗

GHSA-w9j2-pvgh-6h63MODERATE>=1.0.0 <1.15.1 || <0.31.1

Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

source ↗

GHSA-wf5p-g6vw-rhxxMODERATE>=1.0.0 <1.6.0 || >=0.8.1 <0.28.0

Axios Cross-Site Request Forgery Vulnerability

source ↗

GHSA-xhjh-pmcv-23jwLOW>=1.0.0 <1.15.1 || <0.31.1

Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

source ↗

GHSA-xj6q-8x83-jv6gMODERATE>=1.15.2 <1.18.0

Axios: Prototype pollution auth subfields can inject Basic auth

source ↗

GHSA-xx6v-rp6x-q39cMODERATE>=1.0.0 <1.15.1 || <0.31.1

Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

source ↗

MAL-2026-23070.30.4, 1.14.1

Malicious code in axios (npm)

source ↗

Recent changes

v1.18.1Breaking

AxiosURLSearchParams encoder callback switched to arrow function so encoder.call(this) receives the AxiosURLSearchParams instance correctly

Update any code that relies on the previous encoder callback behavior to work with the AxiosURLSearchParams instance context

source ↗

v1.18.1Breaking

Fixed runtime crashes, type definition mismatches, and incorrect error handling paths

source ↗

v1.18.1Breaking

Node HTTP Adapter now guards socket.setKeepAlive for proxy agent streams, accepts path-only URLs when socketPath is configured, defers environment proxy handling to Node, and explicitly passes maxBodyLength through to follow-redirects

source ↗

v1.18.1Breaking

AxiosError#cause is now non-enumerable to prevent circular JSON serialisation failures when errors include nested causes

source ↗

v1.18.0Security

Rejects malformed `http:` and `https:` URLs that omit `//` with `ERR_INVALID_URL`, and tightens prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local `NO_PROXY` matching.

source ↗

v1.18.0Security

Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects to prevent custom auth headers such as API keys from leaking to another origin.

source ↗

v1.18.0Notable

Added `transitional.validateStatusUndefinedResolves` so applications can opt in to treating `validateStatus: undefined` like the option was omitted, while `validateStatus: null` remains the explicit way to accept every status.

source ↗

v1.18.0Breaking

* **Redirect Header Safety:** Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (__#10892__) * **URL And Request Hardening:** Rejects malformed `http:` and `https:` URLs that omit `//` with `ERR_INVALID_URL`, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local `NO_PROXY` matching. (__#11000__)

source ↗

v1.17.0Security

Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance.

source ↗

v1.17.0Security

Guarded `socketPath`, `params`, and `paramsSerializer` reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths.

source ↗

v1.17.0Notable

Added Node HTTP adapter support for zstd response decompression, with `transitional.advertiseZstdAcceptEncoding` controlling whether `zstd` is advertised in `Accept-Encoding`.

source ↗

v1.17.0Breaking

Avoided emitting a null `Authorization` header from the GitHub build helper when `GITHUB_TOKEN` is unset.

source ↗

v1.17.0Breaking

Corrected `AxiosHeaders.toJSON()` return types and updated CommonJS `isCancel` typings to narrow to `CanceledError<T>`.

source ↗

v1.17.0Breaking

Converted `resolveConfig` from an arrow default export to a named function export to avoid webpack and Babel transform interop failures.

source ↗

v1.17.0Breaking

Preserved enumerable symbol keys when cloning plain request data through axios merge logic.

source ↗

v1.17.0Breaking

Silently skipped empty or whitespace-only header names instead of throwing, matching parsed-header behavior and avoiding React Native response crashes.

source ↗

v1.17.0Breaking

Cleared default `Content-Type` for React Native `FormData` so multipart boundaries can be generated correctly.

source ↗

v1.17.0Breaking

Preserved user `httpsAgent` TLS options when tunneling HTTPS requests through HTTP CONNECT proxies.

source ↗

v1.17.0Breaking

Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth.

source ↗

v1.17.0Breaking

* **Config Hardening:** Guarded `socketPath`, `params`, and `paramsSerializer` reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (__#10901__, __#10922__) * **Release Publishing:** Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (__#10926__)

source ↗

v1.16.1Notable

Restored Webpack 4 compatibility for the fetch adapter by fixing an "unexpected token" error caused by incompatible syntax.

source ↗

v1.16.1Breaking

Reverted support for passing a `URL` object as `config.url` due to regressions; this support will be reintroduced in a later release once underlying issues are addressed.

source ↗

v1.16.1Breaking

* **Prototype Pollution Defence-in-Depth:** Hardened `formDataToJSON` against already-polluted `Object.prototype` by walking own properties only, so attacker-controlled keys inherited from a poisoned prototype cannot propagate through deserialization. (__#7413__) * **Proxy Cleartext Leak:** Fixed an issue where HTTPS request data could be transmitted in cleartext to an HTTP proxy under certain configurations. (__#10858__) * **CI Cache Removal:** Removed all GitHub Actions caches as a defence-in-depth measure against cache poisoning vectors in the build pipeline. (__#10882__)

source ↗

v1.16.1Security

Removed all GitHub Actions caches as a defence-in-depth measure against cache poisoning vectors in the build pipeline.

source ↗

v1.16.1Security

Fixed an issue where HTTPS request data could be transmitted in cleartext to an HTTP proxy under certain configurations.

source ↗

v1.16.1Security

Hardened `formDataToJSON` against prototype pollution by walking own properties only, preventing attacker-controlled keys inherited from a poisoned prototype from propagating through deserialization.

source ↗

v1.16.0Security

Fetch adapter now enforces `maxBodyLength` and `maxContentLength` limits for DoS protection and accidental large upload prevention.

source ↗

v1.16.0Notable

Exported the internal `encode` helper from `buildURL` so userland param serializers can reuse the same encoding logic that axios uses internally.

source ↗

v1.16.0Notable

Exposed `ECONNREFUSED` as a constant on `AxiosError` so callers can match connection-refused failures without comparing string literals.

source ↗

v1.16.0Notable

Added support for the QUERY HTTP method across adapters and type definitions.

source ↗

Check what changed for axios since your installed version, live.

Open the playground →