π¨ [security] Update axios 0.21.4 β 1.20.0 (major) - #660
Open
depfu[bot] wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
π¨ Your current dependencies have known security vulnerabilities π¨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.
What changed?
β³οΈ axios (0.21.4 β 1.20.0) Β· Repo Β· Changelog
Security Advisories π¨
π¨ Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
π¨ Axios: Nested axios option objects can consume polluted prototype values
π¨ Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
π¨ Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
π¨ Axios: Prototype pollution auth subfields can inject Basic auth
π¨ Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
π¨ Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
π¨ Axios: Nested axios option objects can consume polluted prototype values
π¨ Axios form serializer maxDepth bypass via {} metatoken
π¨ Axios: Excessive recursion in formDataToJSON can cause denial of service
π¨ Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
π¨ Axios: Prototype pollution gadgets can alter axios request construction
π¨ Axios: Prototype pollution gadgets can alter axios request construction
π¨ Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
π¨ Axios: Excessive recursion in formDataToJSON can cause denial of service
π¨ Axios form serializer maxDepth bypass via {} metatoken
π¨ Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
π¨ Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
π¨ Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
π¨ Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
π¨ Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
π¨ Allocation of Resources Without Limits or Throttling in Axios
π¨ Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
π¨ Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
π¨ axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
π¨ axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions
π¨ axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
π¨ axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
π¨ axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
π¨ axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
π¨ Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution β Incomplete Null-Prototype Fix
π¨ axios's shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)
π¨ Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
π¨ Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
π¨ Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
π¨ Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
π¨ Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
π¨ Axios: Incomplete Fix for CVE-2025-62718 β NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
π¨ Axios: Incomplete Fix for CVE-2025-62718 β NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
π¨ Axios: Header Injection via Prototype Pollution
π¨ Axios: Header Injection via Prototype Pollution
π¨ Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
π¨ Axios' HTTP adapter-streamed uploads bypass maxBodyLength when maxRedirects: 0
π¨ Axios: CRLF Injection in multipart/form-data body via unsanitized blob.type in formDataToStream
π¨ Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
π¨ Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
π¨ Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
π¨ Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
π¨ Axios: unbounded recursion in toFormData causes DoS via deeply nested request data
π¨ Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
π¨ Axios: HTTP adapter streamed responses bypass maxContentLength
π¨ Axios: no_proxy bypass via IP alias allows SSRF
π¨ Axios: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion
π¨ Axios: HTTP adapter streamed responses bypass maxContentLength
π¨ Axios: no_proxy bypass via IP alias allows SSRF
π¨ Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
π¨ Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
π¨ Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
π¨ Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
π¨ Axios HTTP/2 Session Cleanup State Corruption Vulnerability
π¨ Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
π¨ Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
π¨ Axios is vulnerable to DoS attack through lack of data size check
π¨ Axios is vulnerable to DoS attack through lack of data size check
π¨ axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
π¨ axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
π¨ Server-Side Request Forgery in axios
π¨ Axios Cross-Site Request Forgery Vulnerability
π¨ Axios Cross-Site Request Forgery Vulnerability
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by more commits than we can show here.
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands