Skip to content

fix(security): fix security issue in axios via minor version upgrade from 1.13.4 to 1.20.0 - #174

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-134862069-wlbp
Open

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-134862069-wlbp

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary / Description

Upgrade axios to fix critical security vulnerabilities including proxy bypass/SSRF via hostname normalization, prototype pollution header injection, credential leakage on cross-origin redirects, and HTTPS proxy cleartext exposure.

Security Impact — CVE vulnerabilities fixed by this PR

✅ 12 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2025-62718
HIGH
[axios] Improper hostname normalization in NO_PROXY rule checking allows requests to loopback addresses (localhost., [::1]) to bypass proxy protections, enabling proxy bypass and potential SSRF attacks against internal services. This vulnerability permits attackers to reach sensitive services despite configured NO_PROXY protections.
AIKIDO-2026-10741
HIGH
[axios] HTTP client vulnerability allowing prototype pollution through loose object merging, sensitive data exposure via error serialization, and improper proxy/socket handling that could lead to information disclosure or unauthorized access.
CVE-2026-40175
HIGH
[axios] A prototype pollution vulnerability in a third-party dependency can be exploited to inject unsanitized header values into outbound HTTP requests. This could allow attackers to manipulate request headers for potential information disclosure or request forgery attacks.
AIKIDO-2026-291630
HIGH
[axios] HTTP adapter fails to strip custom credential headers (like X-API-Key) during cross-origin redirects, potentially leaking API keys and authentication tokens to unintended hosts. This information disclosure vulnerability affects shared environments where secret headers are set by default.
AIKIDO-2026-10823
HIGH
[axios] HTTP adapter incorrectly routes HTTPS traffic through HTTP proxies in cleartext instead of using CONNECT tunnels, allowing proxy servers to observe sensitive request metadata and payloads that should remain encrypted.
AIKIDO-2026-10509
HIGH
[axios] Prototype pollution vulnerability allows attackers to inject malicious headers into requests through unsafe FormData detection and header merging, potentially enabling authorization bypass or request manipulation.
CVE-2026-44495
MEDIUM
[axios] Contains prototype-pollution gadgets in request config processing that can be exploited if Object.prototype is already polluted by another vulnerability, potentially allowing arbitrary code execution or request manipulation. Requires a separate prototype-pollution vulnerability or attacker control over Object.prototype to be exploitable.
CVE-2026-25639
MEDIUM
[axios] The mergeConfig function crashes with a TypeError when processing configuration objects containing proto as an own property, allowing attackers to trigger denial of service. An attacker can exploit this by providing a malicious configuration object created via JSON.parse().
AIKIDO-2026-38469
MEDIUM
[axios] Accepts malformed HTTP/HTTPS URLs without // (e.g., https:internal.example), allowing attackers to bypass URL allowlists or WAF checks and reach unintended hosts. The vulnerability enables URL validation bypass through silent normalization of invalid URLs.
AIKIDO-2026-10820
MEDIUM
[axios] Request size limits were not enforced in the fetch adapter, allowing responses and bodies to exceed configured limits, potentially causing denial of service or memory exhaustion. The vulnerability has been fixed to properly reject oversized responses and bodies.
AIKIDO-2026-10822
LOW
[axios] A prototype pollution vulnerability in the formDataToJSON helper allows attackers to pollute Object.prototype through specially crafted multipart field names, potentially enabling remote code execution or other malicious actions.
AIKIDO-2026-10819
LOW
[axios] A regular expression vulnerability in browser cookie parsing allowed metacharacters in cookie names to cause incorrect matching or excessive CPU consumption. The vulnerability was fixed by switching to literal string comparison instead of regex-based matching.

Breaking Changes & Upgrade Impact — prefer Warnings / Cautions / ⚠️ sections over implementation sections (upgrade risks, breaking changes, manual migration steps)

✅ Code not affected by breaking changes.

✅ After thoroughly searching the codebase for usages of the features affected by the axios upgrade breaking changes, I found no code that would be impacted:

  1. Header Injection (CRLF): No code dynamically constructs headers with \r or \n characters. All headers are static (e.g., 'Content-Type': 'application/json', Accept: 'application/json') or use the Authorization header with bearer tokens.

  2. Fetch adapter with maxBodyLength/maxContentLength: The codebase does not configure or use the fetch adapter, nor does it set maxBodyLength or maxContentLength limits anywhere.

  3. parseProtocol changes: The codebase does not use the parseProtocol function directly.

  4. Deprecated unescape() replacement: The codebase does not use the unescape() function. URL encoding is handled via encodeURIComponent() in buildUrlWithParams().

  5. Malformed URLs without //: All URLs in the codebase use proper format with // (e.g., https://api.typeform.com, http://test.com, http://typeform.com). The URL construction in buildUrlWithParams() and create-client.ts concatenates properly formatted base URLs with paths.

The upgrade from axios 1.13.4 to 1.18.0 should not cause any breaking changes for this codebase.

All breaking changes by upgrading axios from version 1.13.4 to 1.20.0 (CHANGELOG)

Version Description
1.15.0
Header Injection (CRLF): Headers containing \r or \n characters now throw "Invalid character in header content" instead of being accepted.
1.16.0
Fetch adapter now enforces maxBodyLength and maxContentLength limits that were previously silently ignored.
1.16.0
parseProtocol now strictly requires a colon in the protocol separator; strings that loosely parsed as protocols before may no longer match.
1.16.0
Deprecated unescape() replaced with modern UTF-8 encoding; non-ASCII URL handling is now spec-correct and consumers depending on legacy unescape() quirks may see different output bytes.
1.18.0
Malformed http: and https: URLs that omit // are now rejected with ERR_INVALID_URL.
1.20.0
HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases.
1.20.0
Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects, with documented compatibility effects on Fetch redirect behavior, custom implementations, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection.

Fix Details / Technical Implementation (detailed write-up of what was changed and why)

🤖 Remediation details

Fix axios security vulnerabilities (multiple HIGH/MEDIUM/LOW CVEs)

Short summary

This PR remediates multiple security vulnerabilities in axios by bumping its declared version floor in the root package.json. The axios package is a direct runtime dependency of this project; the fix updates both the manifest range and the resolved entry in yarn.lock.

axios

axios was declared as a direct dependency at ^1.13.4, resolving to 1.13.4, which falls within multiple vulnerable ranges covering a series of HIGH, MEDIUM, and LOW severity advisories. The declared range in package.json was raised to ^1.18.0, and yarn install --ignore-engines --ignore-scripts was run to refresh yarn.lock, which resolved axios to 1.20.0. No parent-chain analysis or resolutions override was required because axios is a direct dependency and the new range is semver-compatible with the existing ^ specifier.

Version changes

Package From To Why updated
axios ^1.13.4 (resolved 1.13.4) ^1.18.0 (resolved 1.20.0) Direct CVE fix

@pr-auditor

pr-auditor Bot commented Oct 6, 2026

Copy link
Copy Markdown

✅ Security Analysis Results

No security issues found. 2 files reviewed.


@pr-auditor rescan to re-run · Powered by Claude Sonnet 5 · Docs · #security-engineering-team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants