Skip to content

fix(deps): vuln axios (minor → 1.20.0) [example/package.json] - #1472

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/example/1-1791199309
Closed

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
developfrom
engraver-auto-version-upgrade/minorpatch/npm/example/1-1791199309

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • example/package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
axios 1.18.0 1.20.0 minor Direct 14 HIGH, 9 MEDIUM

Security Details

🚨 Critical & High Severity (14 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
axios GHSA-mghh-pgcx-3jjj HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location 1.18.0 1.20.0 -
axios CVE-2026-101907 HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF 1.18.0 - -
axios GHSA-542g-h47m-68v8 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization 1.18.0 1.20.0 -
axios CVE-2026-101901 HIGH Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization 1.18.0 - -
axios CVE-2026-101898 HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls 1.18.0 - -
axios GHSA-3pq3-5fj3-cg6v HIGH Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls 1.18.0 1.20.0 -
axios CVE-2026-101905 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection 1.18.0 - -
axios GHSA-c29m-xwm3-cm6r HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) 1.18.0 1.20.0 -
axios GHSA-r4gj-5m52-g5wh HIGH Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF 1.18.0 1.20.0 -
axios GHSA-m8m8-qj5v-23w3 HIGH Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection 1.18.0 1.20.0 -
axios CVE-2026-101903 HIGH Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) 1.18.0 - -
axios CVE-2026-101909 HIGH Axios: Prototype Pollution Gadget in axios toFormData Options 1.18.0 - -
axios GHSA-x97p-jq2g-jp4f HIGH Axios: Prototype Pollution Gadget in axios toFormData Options 1.18.0 0.34.0 -
axios CVE-2026-101906 HIGH Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location 1.18.0 - -
ℹ️ Other Vulnerabilities (9)
Package CVE Severity Summary Unsafe Version Fixed In Case
axios GHSA-44g4-m2mj-wpvx MODERATE Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges 1.18.0 1.20.0 -
axios CVE-2026-101904 MODERATE Axios: Header Injection via Inherited headers After Minimal Interceptor 1.18.0 - -
axios GHSA-j8rh-479h-cp32 MODERATE Axios: Header Injection via Inherited headers After Minimal Interceptor 1.18.0 1.20.0 -
axios GHSA-9fr6-4gfg-395g MODERATE Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 1.18.0 0.34.0 -
axios CVE-2026-101902 MODERATE Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method 1.18.0 - -
axios GHSA-vh66-26gq-q6x8 MODERATE Axios: Prototype pollution gadget in fetch adapter can alter outbound requests 1.18.0 1.20.0 -
axios CVE-2026-101908 MODERATE Axios: Prototype pollution gadget in fetch adapter can alter outbound requests 1.18.0 - -
axios CVE-2026-101900 MODERATE Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders 1.18.0 - -
axios GHSA-4hqw-qxg8-jxx2 MODERATE Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders 1.18.0 1.20.0 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant