Is axios healthy, maintained, and safe?
Maintained, but watch it — axios has real signals (drift, thin maintenance, or advisories) worth tracking.
The verdict
axios earns a health score of 40/100, a medium risk rating, computed deterministically from live npm release history, maintainer data, and the OSV vulnerability database. Maintained, but watch it — axios has real signals (drift, thin maintenance, or advisories) worth tracking.
Its most recent release shipped on 22 June 2026 — 35 days ago — so development is clearly active. Across 144 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. Ownership rests on a single maintainer — a bus-factor of one, meaning one person's availability is a single point of failure for everyone downstream.
OSV lists 44 known advisories for axios, including 18 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.
axios is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own package.json through the free health check, or have OSPulse monitor your whole dependency tree continuously.
Evidence trail — deterministic, auditable
Known vulnerabilities (44)
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
- GHSA-42h9-826w-cgv3 ↗MODERATE
Axios: Excessive recursion in formDataToJSON can cause denial of service
Denial of Service in axios
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
Axios is vulnerable to DoS attack through lack of data size check
Axios vulnerable to Server-Side Request Forgery
Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Axios: Header Injection via Prototype Pollution
Allocation of Resources Without Limits or Throttling in Axios
- GHSA-7q8q-rj6j-mhjq ↗MODERATE
Axios: Nested axios option objects can consume polluted prototype values
axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
Server-Side Request Forgery in axios
axios Inefficient Regular Expression Complexity vulnerability
- GHSA-f4gw-2p7v-4548 ↗MODERATE
Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
- GHSA-hcpx-6fm6-wx23 ↗MODERATE
Axios form serializer maxDepth bypass via {} metatoken
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
- GHSA-jqh4-m9w3-8hp9 ↗MODERATE
Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
Axios: no_proxy bypass via IP alias allows SSRF
- GHSA-mmx7-hfxf-jppx ↗MODERATE
Axios: Prototype pollution gadgets can alter axios request construction
- GHSA-mwf2-3pr3-8698 ↗MODERATE
Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
- GHSA-pmv8-rq9r-6j72 ↗MODERATE
Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
Axios HTTP/2 Session Cleanup State Corruption Vulnerability
Axios: HTTP adapter streamed responses bypass maxContentLength
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Axios Cross-Site Request Forgery Vulnerability
Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- GHSA-xj6q-8x83-jv6g ↗MODERATE
Axios: Prototype pollution auth subfields can inject Basic auth
Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
Malicious code in axios (npm)
Key facts
- Latest version
- v1.18.1
- Last release
- 22 June 2026 (35 days ago)
- Total releases
- 144
- First release
- 29 August 2014
- Package age
- 11.9 years
- Maintainers
- 1
- Known advisories
- 44
- Confidence
- High
Frequently asked
Is axios still maintained?
Yes — axios released as recently as 22 June 2026 (35 days ago), so it is actively maintained.
Does axios have known security vulnerabilities?
Yes — OSV lists 44 advisories for axios. See the advisory list on this page for the OSV/GHSA identifiers.
Is axios safe to use?
Maintained, but watch it — axios has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 40/100 (medium risk) based on release recency, cadence, maintainer bus factor and known vulnerabilities.
Other npm packages we've checked
axios is one package. What about the other hundreds in your tree?
Paste your own package.json into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.
Data from the npm registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.
