Jay
6 exploits
Active since Feb 2026
Axios: Prototype pollution read-side gadgets in HTTP adapter allow credential injection and request hijacking
CVSS 7.4
Axios <1.15.0 and <0.31.0 NO_PROXY - Server-Side Request Forgery
CVSS 9.9
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVSS 4.8
Axios <1.15.0 and <0.31.0 NO_PROXY - Server-Side Request Forgery
CVSS 9.9
axios < 0.30.3 and 1.0.0-1.13.5 - Denial of Service via __proto__ Property in Configuration Object
CVSS 7.5