OSPulse

Is axios healthy, maintained, and safe?

40/ 100
axiosv1.18.1
Medium riskconfidence: Highview on npmjs.com

Maintained, but watch it — axios has real signals (drift, thin maintenance, or advisories) worth tracking.

vital-signs traceirregular · weakening

The verdict

axios earns a health score of 40/100, a medium risk rating, computed deterministically from live npm release history, maintainer data, and the OSV vulnerability database. Maintained, but watch it — axios has real signals (drift, thin maintenance, or advisories) worth tracking.

Its most recent release shipped on 22 June 2026 — 35 days ago — so development is clearly active. Across 144 releases the cadence has been steady, which is a good sign of an ongoing maintenance rhythm. Ownership rests on a single maintainer — a bus-factor of one, meaning one person's availability is a single point of failure for everyone downstream.

OSV lists 44 known advisories for axios, including 18 high. Review whether your version is in the affected range and whether a fixed release is available before depending on it. Each advisory is listed with its OSV/GHSA identifier below.

axios is usable but carries real signals — pin versions, watch for new advisories, and keep a fallback in mind. This is a one-time snapshot of a single package — real projects depend on dozens or hundreds of packages, and any one of them can drift or be compromised between releases. Run your own package.json through the free health check, or have OSPulse monitor your whole dependency tree continuously.

Evidence trail — deterministic, auditable

Last release recency
35 days ago · active
Release cadence
steady · typical gap ~11d
Maintainer bus factor
single maintainer — bus factor 1
-15
Known vulnerabilities (OSV)
44 advisories · 18 high
-45
Package age
11.9 years · 144 releases

Known vulnerabilities (44)

  • GHSA-35jp-ww65-95whHIGHCVE-2026-44494

    axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

  • GHSA-3g43-6gmg-66jwHIGHCVE-2026-44495

    axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

  • GHSA-3p68-rc4w-qgx5MODERATECVE-2025-62718

    Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF

  • GHSA-3w6x-2g7m-8v23MODERATECVE-2026-42044

    Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`

  • Axios: Excessive recursion in formDataToJSON can cause denial of service

  • GHSA-42xw-2xvc-qx8mHIGHCVE-2019-10742

    Denial of Service in axios

  • GHSA-43fc-jf86-j433HIGHCVE-2026-25639

    Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

  • GHSA-445q-vr5w-6q77MODERATECVE-2026-42037

    Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream

  • GHSA-4hjh-wcwx-xvwjHIGHCVE-2025-58754

    Axios is vulnerable to DoS attack through lack of data size check

  • GHSA-4w2v-q235-vp99MODERATECVE-2020-28168

    Axios vulnerable to Server-Side Request Forgery

  • GHSA-5c9x-8gcm-mpgxMODERATECVE-2026-42034

    Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0

  • GHSA-62hf-57xw-28j9MODERATECVE-2026-42039

    Axios: unbounded recursion in toFormData causes DoS via deeply nested request data

  • GHSA-654m-c8p4-x5fpLOWCVE-2026-44489

    Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

  • GHSA-6chq-wfr3-2hj9HIGHCVE-2026-42035

    Axios: Header Injection via Prototype Pollution

  • GHSA-777c-7fjr-54vfHIGHCVE-2026-44488

    Allocation of Resources Without Limits or Throttling in Axios

  • Axios: Nested axios option objects can consume polluted prototype values

  • GHSA-898c-q2cr-xwhgMODERATECVE-2026-44490

    axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

  • GHSA-8hc4-vh64-cxmjHIGHCVE-2024-39338

    Server-Side Request Forgery in axios

  • GHSA-cph5-m8f7-6c5xHIGHCVE-2021-3749

    axios Inefficient Regular Expression Complexity vulnerability

  • Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios

  • GHSA-fvcv-3m26-pcqxMODERATECVE-2026-40175

    Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain

  • Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning

  • Axios form serializer maxDepth bypass via {} metatoken

  • GHSA-hfxv-24rg-xrqfHIGHCVE-2026-44496

    Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

  • GHSA-j5f8-grm9-p9fcHIGHCVE-2026-44486

    Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

  • Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`

  • GHSA-jr5f-v2jv-69x6HIGHCVE-2025-27152

    axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL

  • GHSA-m7pr-hjqh-92cmMODERATECVE-2026-42038

    Axios: no_proxy bypass via IP alias allows SSRF

  • Axios: Prototype pollution gadgets can alter axios request construction

  • Axios: HTTP/2 streamed uploads bypass `maxBodyLength`

  • GHSA-p92q-9vqr-4j8vHIGHCVE-2026-44487

    Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter

  • GHSA-pf86-5x62-jrwfHIGHCVE-2026-42033

    Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking

  • GHSA-pjwm-pj3p-43mvHIGHCVE-2026-44492

    axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)

  • Axios: Deep formToJSON Key Recursion Can Cause Denial of Service

  • GHSA-pmwg-cvhr-8vh7HIGHCVE-2026-42043

    Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0

  • GHSA-q8qp-cvcw-x6jjHIGHCVE-2026-42264

    Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

  • GHSA-qj83-cq47-w5f8MODERATECVE-2026-39865

    Axios HTTP/2 Session Cleanup State Corruption Vulnerability

  • GHSA-vf2m-468p-8v99MODERATECVE-2026-42036

    Axios: HTTP adapter streamed responses bypass maxContentLength

  • GHSA-w9j2-pvgh-6h63MODERATECVE-2026-42041

    Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy

  • GHSA-wf5p-g6vw-rhxxMODERATECVE-2023-45857

    Axios Cross-Site Request Forgery Vulnerability

  • GHSA-xhjh-pmcv-23jwLOWCVE-2026-42040

    Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams

  • Axios: Prototype pollution auth subfields can inject Basic auth

  • GHSA-xx6v-rp6x-q39cMODERATECVE-2026-42042

    Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion

  • MAL-2026-2307UNKNOWNGHSA-fw8c-xr5c-95f9

    Malicious code in axios (npm)

Key facts

Latest version
v1.18.1
Last release
22 June 2026 (35 days ago)
Total releases
144
First release
29 August 2014
Package age
11.9 years
Maintainers
1
Known advisories
44
Confidence
High

Frequently asked

Is axios still maintained?

Yes — axios released as recently as 22 June 2026 (35 days ago), so it is actively maintained.

Does axios have known security vulnerabilities?

Yes — OSV lists 44 advisories for axios. See the advisory list on this page for the OSV/GHSA identifiers.

Is axios safe to use?

Maintained, but watch it — axios has real signals (drift, thin maintenance, or advisories) worth tracking. OSPulse rates it 40/100 (medium risk) based on release recency, cadence, maintainer bus factor and known vulnerabilities.

Other npm packages we've checked

Browse all checked packages →

axios is one package. What about the other hundreds in your tree?

Paste your own package.json into the free health check for an instant snapshot — or let OSPulse monitor your whole dependency tree continuously, before your CVE scanner wakes up.

Data from the npm registry & OSV.dev · snapshot generated 2026-07-27 · scores are deterministic and recomputed on each refresh.