Skip to content

[Security] axios — No CVE listed #41

Description

@bitskc

Vulnerability in axios

Severity: high
CVE: No CVE listed
Vulnerable range: 1.0.0 - 1.17.0
Advisory: GHSA-42h9-826w-cgv3; GHSA-pmv8-rq9r-6j72; GHSA-jqh4-m9w3-8hp9; GHSA-mmx7-hfxf-jppx; GHSA-f4gw-2p7v-4548; GHSA-gcfj-64vw-6mp9; GHSA-hcpx-6fm6-wx23; GHSA-7q8q-rj6j-mhjq; GHSA-mwf2-3pr3-8698; GHSA-xj6q-8x83-jv6g
Description: Axios: Excessive recursion in formDataToJSON can cause denial of service; Axios: Deep formToJSON Key Recursion Can Cause Denial of Service; Axios: Fetch adapter ReadableStream uploads bypass maxBodyLength; Axios: Prototype pollution gadgets can alter axios request construction; Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios; Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning; Axios form serializer maxDepth bypass via {} metatoken; Axios: Nested axios option objects can consume polluted prototype values; Axios: HTTP/2 streamed uploads bypass maxBodyLength; Axios: Prototype pollution auth subfields can inject Basic auth

Fix recommendation

Run npm audit fix to resolve this vulnerability.

Affected paths

node_modules/axios

Automatically detected by dependency vulnerability scan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions