Vulnerabilities/

Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

Severity:
High

Description

Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header.

Recommendation

Update the axios package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
axios
Anything's wrong? Let us know Last updated on June 12, 2026