Vulnerabilities/

Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

Severity:
High

Description

Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters.

Recommendation

Update the axios package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
axios
Anything's wrong? Let us know Last updated on June 11, 2026