Exposure of Axios

JavaScript libraries
69
exposure score
110,560
sites use
0
exploited
0
critical
Vexday analysis

Com 30 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Axios apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças oportunistas. Ainda assim, o volume merece atenção: 25 das 30 vulnerabilidades surgiram nos últimos 90 dias, indicando aceleração recente no ritmo de descoberta e reporte. O tipo de falha mais comum é CWE-1321 (poluição de protótipo), padrão que, quando presente em bibliotecas amplamente utilizadas, pode ter impacto em cadeia dependendo do contexto de cada aplicação. A CVE mais perigosa atualmente rastreada é CVE-2019-10742, com score EPSS de 0,0598, o que representa probabilidade relativamente baixa de exploração a curto prazo, mas equipes que dependem de versões legadas devem priorizá-la na triagem.

CVEs

40 results
CVE-2019-10742Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after EPSS 6.0%CVE-2026-25639HIGHAxios affected by Denial of Service via __proto__ Key in mergeConfigEPSS 2.5%CVE-2026-40175MEDIUMAxios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainEPSS 1.9%CVE-2025-62718MEDIUMAxios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRFEPSS 1.2%CVE-2025-58754HIGHAxios is vulnerable to DoS attack through lack of data size checkEPSS 1.1%CVE-2026-44494HIGHAxios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`EPSS 1.0%CVE-2026-44492HIGHAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)EPSS 0.9%CVE-2026-42033HIGHAxios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request HijackingEPSS 0.8%CVE-2025-27152HIGHPossible SSRF and Credential Leakage via Absolute URL in axios RequestsEPSS 0.8%CVE-2026-39865MEDIUMAxios HTTP/2 Session Cleanup State Corruption VulnerabilityEPSS 0.7%CVE-2026-42039MEDIUMAxios: unbounded recursion in toFormData causes DoS via deeply nested request dataEPSS 0.7%CVE-2026-42264HIGHAxios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijackingEPSS 0.7%CVE-2026-44487HIGHAxios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP AdapterEPSS 0.7%CVE-2026-42043HIGHAxios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0EPSS 0.7%CVE-2026-44486HIGHAxios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connectionEPSS 0.7%CVE-2026-44496HIGHAxios: Regular Expression Denial of Service (ReDoS) via Cookie Name InjectionEPSS 0.6%CVE-2026-44488HIGHAxios: Allocation of Resources Without Limits or Throttling in axiosEPSS 0.6%CVE-2026-42041MEDIUMAxios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge StrategyEPSS 0.6%CVE-2026-42044MEDIUMAxios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`EPSS 0.6%CVE-2026-44495HIGHAxios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config MergeEPSS 0.5%