Improper Input Validation Affecting axios package, versions >=1.12.0 <1.20.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.55% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Input Validation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-AXIOS-20245058
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditEr3n

Introduced: 28 Sep 2026

NewCVE-2026-101900  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade axios to version 1.20.0 or higher.

Overview

axios is a promise-based HTTP client for the browser and Node.js.

Affected versions of this package are vulnerable to Improper Input Validation via insufficient hardening of runtime option handling in the fetch and HTTP adapters, where user-supplied fetchOptions are merged into the resolved request options without sanitization. An attacker who can influence request configuration can inject or override internal Axios-owned options (such as body, headers, method, signal, credentials), leading to integrity impact on the downstream system receiving the request.

CVSS Base Scores

version 4.0
version 3.1