Description
When Axios runs on Node.js and is given a URL with the data: scheme, it does not perform HTTP. Instead, its Node http adapter decodes the entire payload into memory (Buffer/Blob) and returns a synthetic 200 response.
Recommendation
Update the axios package to the latest compatible version. Followings are version details:
Affected version(s): **>= 0.28.0, < 0.30.2 >= 1.0.0, < 1.12.0** Patched version(s): **0.30.2 1.12.0**
References
Related Issues
- DiracX-Web is vulnerable to attack through an Open Redirect on its login page - CVE-2025-54066
- x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting - CVE-2022-25646
- Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity - CVE-2025-58451
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
You might also like:
- Tags:
- npm
- axios
Anything's wrong? Let us know Last updated on January 16, 2026


