5.3

CVSS3.1

CVE-2026-42034 - Axios: HTTP adapter streamed uploads bypass maxBodyLength when maxRedirects: 0

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets strict body limits…

📅 Published: April 24, 2026, 5:59 p.m. 🔄 Last Modified: April 24, 2026, 5:59 p.m.

5.3

CVSS3.1

CVE-2026-42037 - Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart constructor in lib/helpers/formDataToStream.js interpolates value.type directly into the Content-Type header of each multipart part without sanitizing CRLF (\r\n) sequences. An attacker w…

📅 Published: April 24, 2026, 5:58 p.m. 🔄 Last Modified: April 24, 2026, 5:58 p.m.

6.8

CVSS3.1

CVE-2026-42038 - Axios: no_proxy bypass via IP alias allows SSRF

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostname normalization bypass is incomplete. When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The shouldBypassProxy…

📅 Published: April 24, 2026, 5:57 p.m. 🔄 Last Modified: April 24, 2026, 5:57 p.m.

4.8

CVSS3.1

CVE-2026-42041 - Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be t…

📅 Published: April 24, 2026, 5:55 p.m. 🔄 Last Modified: April 24, 2026, 5:55 p.m.

7.2

CVSS3.1

CVE-2026-42043 - Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subn…

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due …

📅 Published: April 24, 2026, 5:54 p.m. 🔄 Last Modified: April 24, 2026, 5:54 p.m.

6.5

CVSS3.1

CVE-2026-42044 - Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modificatio…

📅 Published: April 24, 2026, 5:49 p.m. 🔄 Last Modified: April 24, 2026, 5:50 p.m.

3.7

CVSS3.1

CVE-2026-42040 - Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character mapping (charMap) at line 21 that reverses the safe percent-encoding of null bytes. After encodeURIComponent('\x00') correc…

📅 Published: April 24, 2026, 5:40 p.m. 🔄 Last Modified: April 24, 2026, 5:40 p.m.

7.4

CVSS3.1

CVE-2026-42035 - Axios: Header Injection via Prototype Pollution

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exploits duck-type ch…

📅 Published: April 24, 2026, 5:38 p.m. 🔄 Last Modified: April 24, 2026, 5:38 p.m.

7.4

CVSS3.1

CVE-2026-42033 - Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the appl…

📅 Published: April 24, 2026, 5:36 p.m. 🔄 Last Modified: April 24, 2026, 5:36 p.m.

8.7

CVSS4.0

CVE-2026-41680 - Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab, and a newline (\x09\x0b\n)—an unauthenticated attacker can trigger an infinite recursion loop duri…

📅 Published: April 24, 2026, 5:26 p.m. 🔄 Last Modified: April 24, 2026, 5:26 p.m.
Total resulsts: 347851
Page 137 of 34,786
« previous page » next page
Filters