org.webjars.npm:axios

Licenses: MIT

Direct Vulnerabilities

Known vulnerabilities in the org.webjars.npm:axios package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Insertion of Sensitive Information Into Sent Data

[,1.16.0)
  • M
Allocation of Resources Without Limits or Throttling

[1.7.1,1.16.0)
  • H
Insertion of Sensitive Information Into Sent Data

[,1.16.0)
  • M
Regular Expression Denial of Service (ReDoS)

[,1.16.0)
  • H
Prototype Pollution

[0.19.0,1.15.2)
  • H
Server-side Request Forgery (SSRF)

[,1.16.0)
  • H
Prototype Pollution

[,1.16.0)
  • M
Prototype Pollution

[,1.16.0)
  • M
Prototype Pollution

[1.15.2,1.16.0)
  • C
Prototype Pollution

[1.0.0,1.15.2)
  • M
Server-side Request Forgery (SSRF)

[,1.15.1)
  • M
Incomplete List of Disallowed Inputs

[1.15.0,1.15.1)
  • M
Improper Encoding or Escaping of Output

[,1.15.1)
  • C
HTTP Response Splitting

[,1.15.1)
  • M
Allocation of Resources Without Limits or Throttling

[,1.15.1)
  • M
Allocation of Resources Without Limits or Throttling

[,1.15.1)
  • M
Insertion of Sensitive Information Into Sent Data

[,1.15.1)
  • M
CRLF Injection

[1.3.0,1.15.1)
  • C
Prototype Pollution

[,1.15.1)
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

[1.0.0,1.15.2)
  • H
Uncontrolled Recursion

[,1.15.1)
  • M
Prototype Pollution

[,1.15.1)
  • H
HTTP Response Splitting

[,1.15.0)
  • M
Unintended Proxy or Intermediary ('Confused Deputy')

[,1.15.0)
  • H
Allocation of Resources Without Limits or Throttling

[1.13.0,1.14.0)
  • H
Prototype Pollution

[,1.13.5)
  • M
Allocation of Resources Without Limits or Throttling

[,0.30.2)[1.1.2,1.12.2)
  • M
Server-side Request Forgery (SSRF)

[,1.8.3)
  • M
Server-side Request Forgery (SSRF)

[,1.8.3)
  • H
Server-side Request Forgery (SSRF)

[,1.7.4)
  • H
Prototype Pollution

[,1.6.5)
  • M
Regular Expression Denial of Service (ReDoS)

[,1.6.5)
  • H
Cross-site Request Forgery (CSRF)

[1.0.0,1.6.0)[0.8.1,0.28.0)
  • H
Regular Expression Denial of Service (ReDoS)

[,0.21.4)
  • M
Server-Side Request Forgery (SSRF)

[0,0.21.1)
  • M
Denial of Service (DoS)

[,0.19.0)

Package versions

71 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
1.18.123 Jun, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.18.016 Jun, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.17.03 Jun, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.16.115 May, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.16.013 May, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
1.15.222 Apr, 2026
  • 0
    C
  • 3
    H
  • 5
    M
  • 0
    L
1.15.121 Apr, 2026
  • 1
    C
  • 5
    H
  • 4
    M
  • 0
    L
1.15.013 Apr, 2026
  • 3
    C
  • 6
    H
  • 12
    M
  • 0
    L
1.14.031 Mar, 2026
  • 3
    C
  • 7
    H
  • 12
    M
  • 0
    L
1.13.615 Mar, 2026
  • 3
    C
  • 8
    H
  • 12
    M
  • 0
    L