Vulnerability in axios
Severity: high
CVE: No CVE listed
Vulnerable range: 1.0.0 - 1.17.0
Advisory: GHSA-42h9-826w-cgv3; GHSA-pmv8-rq9r-6j72; GHSA-jqh4-m9w3-8hp9; GHSA-mmx7-hfxf-jppx; GHSA-f4gw-2p7v-4548; GHSA-gcfj-64vw-6mp9; GHSA-hcpx-6fm6-wx23; GHSA-7q8q-rj6j-mhjq; GHSA-mwf2-3pr3-8698; GHSA-xj6q-8x83-jv6g
Description: Axios: Excessive recursion in formDataToJSON can cause denial of service; Axios: Deep formToJSON Key Recursion Can Cause Denial of Service; Axios: Fetch adapter ReadableStream uploads bypass maxBodyLength; Axios: Prototype pollution gadgets can alter axios request construction; Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios; Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning; Axios form serializer maxDepth bypass via {} metatoken; Axios: Nested axios option objects can consume polluted prototype values; Axios: HTTP/2 streamed uploads bypass maxBodyLength; Axios: Prototype pollution auth subfields can inject Basic auth
Fix recommendation
Run npm audit fix to resolve this vulnerability.
Affected paths
Automatically detected by dependency vulnerability scan.
Vulnerability in
axiosSeverity: high
CVE: No CVE listed
Vulnerable range: 1.0.0 - 1.17.0
Advisory: GHSA-42h9-826w-cgv3; GHSA-pmv8-rq9r-6j72; GHSA-jqh4-m9w3-8hp9; GHSA-mmx7-hfxf-jppx; GHSA-f4gw-2p7v-4548; GHSA-gcfj-64vw-6mp9; GHSA-hcpx-6fm6-wx23; GHSA-7q8q-rj6j-mhjq; GHSA-mwf2-3pr3-8698; GHSA-xj6q-8x83-jv6g
Description: Axios: Excessive recursion in formDataToJSON can cause denial of service; Axios: Deep formToJSON Key Recursion Can Cause Denial of Service; Axios: Fetch adapter
ReadableStreamuploads bypassmaxBodyLength; Axios: Prototype pollution gadgets can alter axios request construction; Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios; Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning; Axios form serializer maxDepth bypass via {} metatoken; Axios: Nested axios option objects can consume polluted prototype values; Axios: HTTP/2 streamed uploads bypassmaxBodyLength; Axios: Prototype pollution auth subfields can inject Basic authFix recommendation
Run
npm audit fixto resolve this vulnerability.Affected paths
Automatically detected by dependency vulnerability scan.