Vulnerabilities
Vulnerable Software
Axios:  >> Axios  >> 0.13.0  Security Vulnerabilities
axios is a promise based HTTP client for the browser and node.js. The issue occurs when passing absolute URLs rather than protocol-relative URLs to axios. Even if ⁠baseURL is set, axios sends the request to the specified absolute URL, potentially causing SSRF and credential leakage. This issue impacts both server-side and client-side usage of axios. This issue is fixed in 1.8.2.
CVSS Score
7.7
EPSS Score
0.008
Published
2025-03-07
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.
EPSS Score
0.004
Published
2025-01-29
axios is vulnerable to Inefficient Regular Expression Complexity
CVSS Score
7.5
EPSS Score
0.085
Published
2021-08-31
Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.
CVSS Score
7.5
EPSS Score
0.055
Published
2019-05-07


Contact Us

Shodan ® - All rights reserved