1 known bug in axios, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
| Severity | Affected | Fixed in | Title | Status | Source |
|---|---|---|---|---|---|
| high | 1.7.0 - 1.7.3 | 1.7.4 | SSRF via redirect when followRedirects is true and URL has @ char axios followed redirects to arbitrary hosts when the original URL contained `@` (CVE-2024-39338). Security fix in 1.7.4. | closed | github:#6463 |
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/npm/axios