NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #237 most downloaded on npm
Promise based HTTP client for the browser and node.js
Last release 18 days ago
16 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
52 versions withdrawn
withdrawn after publishing
12 years old
145 releases · first in 2014
⚠️ Breaking Changes & Deprecations
This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
Full Changelog (v1.19.0...v1.20.0)
One column per quarter.
…versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx ( GHSA-hmw2-7cc7-3qxx ).
This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.
We are thrilled to welcome our new contributors. Thank you for helping improve Axios:
Full Changelog (v1.18.1...v1.19.0)
This release focuses on Node HTTP adapter fixes, safer AxiosError serialisation, runtime/type correctness fixes, documentation updates, and dependency
This release focuses on Node HTTP adapter fixes, safer AxiosError serialisation, runtime/type correctness fixes, documentation updates, and dependency maintenance.
encoder.call(this) receives the AxiosURLSearchParams instance correctly. (#11019)Documentation: Documented sensitive headers and status transition behaviour, prepared cleaned-up docs, added Deno install instructions, and clarified that request data is request-specific (#11007, #11010, #11023, #11025)
Dependencies: Bumped vite, rollup, form-data, js-yaml, and multer across the root project, docs, smoke tests, and module test workspaces. (#11011, #11012, #11013, #11014, #11015, #11016, #11017, #11026)
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
This release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependenci
This release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.
Redirect Header Safety: Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (#10892)
URL And Request Hardening: Rejects malformed http: and https: URLs that omit // with ERR_INVALID_URL, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local NO_PROXY matching. (#11000)
transitional.validateStatusUndefinedResolves so applications can opt in to treating validateStatus: undefined like the option was omitted, while validateStatus: null remains the explicit way to accept every status. (#10899)Documentation: Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the proxy request config as Node.js-only in the advanced docs. (#10984, #10988, #10992, #10995)
Dependencies: Bumped @babel/core, @babel/preset-env, @commitlint/cli, @commitlint/config-conventional, @rollup/plugin-babel, @rollup/plugin-commonjs, @vitest/browser, @vitest/browser-playwright, eslint, lint-staged, rollup, vitest, and actions/checkout. (#10989, #10996, #10997)
Release Metadata: Prepared the 1.18.0 release by updating package metadata and the runtime VERSION value. (#11003)
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
This release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regre
This release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.
socketPath, params, and paramsSerializer reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (#10901, #10922)transitional.advertiseZstdAcceptEncoding controlling whether zstd is advertised in Accept-Encoding. (#6792, #10920)httpsAgent TLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (#10957)Content-Type for React Native FormData so multipart boundaries can be generated correctly. (#10898)resolveConfig from an arrow default export to a named function export to avoid webpack and Babel transform interop failures. (#10891)AxiosHeaders.toJSON() return types and updated CommonJS isCancel typings to narrow to CanceledError<T>. (#10956, #10952)Authorization header from the GitHub build helper when GITHUB_TOKEN is unset. (#10931)Http2Sessions into its own helper module and added direct unit coverage for session pooling, timeout, and cleanup behavior. (#10861)files allowlist and dropping unneeded unminified bundle source maps. (#10939)fs-extra, qs, docs dependencies, and GitHub Actions dependencies including actions/dependency-review-action and zizmorcore/zizmor-action. (#10871, #10879, #10918, #10919, #10934, #10947, #10954, #10960)We are thrilled to welcome our new contributors. Thank you for helping improve axios:
This release ships a defence-in-depth fix for prototype pollution in formDataToJSON , hardens proxy and CI workflows, restores Webpack 4 compatibility
This release ships a defence-in-depth fix for prototype pollution in formDataToJSON, hardens proxy and CI workflows, restores Webpack 4 compatibility for the fetch adapter, and includes several small bug fixes and maintenance improvements.
formDataToJSON against already-polluted Object.prototype by walking own properties only, so attacker-controlled keys inherited from a poisoned prototype cannot propagate through deserialization. (#7413)fromDataURI regex to match RFC 2397 more strictly, fixing edge cases in data: URL handling. (#10829)ProgressEvent payloads emitted by some environments during XHR upload, preventing crashes when loaded / total are missing or invalid. (#10868)parseReviver context.source optional in the type definitions to align with the ES2023 specification. (#10837)URL object as config.url (originally #10866) due to regressions; this support will be reintroduced in a later release once the underlying issues are addressed. (#10874)toJSONObject with a WeakSet, improving performance and memory behaviour on large nested structures. (#10832)composeSignals to use a clearer early-return structure, simplifying the cancellation/abort composition path. (#10844)AGENTS.md and related contributor-guide updates for both human and AI agents, plus post-release documentation improvements. (#10835, #10841)eject example to reference the correct instance, and corrected the Buzzoid sponsor description in the README. (#10836, #10853, #10856)@commitlint/cli from 20.5.0 to 20.5.2. (#10846)We are thrilled to welcome our new contributors. Thank you for helping improve axios:
Deprecated unescape() replaced with modern UTF-8 encoding. Non-ASCII URL handling is now spec-correct; consumers depending on legacy unescape() quirks…
This release adds support for the QUERY HTTP method and a new ECONNREFUSED error constant, lands a substantial wave of HTTP, fetch, and XHR adapter bug fixes around redirects, aborts, headers, and timeouts, and welcomes 23 new contributors.
A handful of fixes in this release are either security-adjacent or change observable behaviour. Please review before upgrading:
maxBodyLength and maxContentLength. These limits were silently ignored on the fetch adapter prior to 1.16.0 — anyone relying on them as a safety net (DoS protection, accidental large uploads) had no protection. (#10795)Host headers. Previously, the proxy path could overwrite a custom Host. Virtual-host-style routing through a proxy will now behave correctly. (#10822)https://user:p%40ss@host), the decoded value is what now goes on the wire. (#10825)parseProtocol now strictly requires a colon in the protocol separator. Strings that loosely parsed as protocols before may no longer match. (#10729)unescape() replaced with modern UTF-8 encoding. Non-ASCII URL handling is now spec-correct; consumers depending on legacy unescape() quirks may see different output bytes. (#7378)transformRequest input typing change was reverted. The typing change introduced in #10745 was reverted in #10810 after follow-up review — net behavior is unchanged from 1.15.2. (#10745, #10810)ECONNREFUSED as a constant on AxiosError so callers can match connection-refused failures without comparing string literals (closes #6485). (#10680)encode helper from buildURL so userland param serializers can reuse the same encoding logic that axios uses internally. (#6897)requestDetails argument on beforeRedirect, preserved user-supplied Host headers when forwarding through a proxy, and properly URL-decoded basic auth credentials. (#10794, #10800, #6241, #10822, #10825)AxiosError when a stream is aborted after headers arrive, honoured the timeout option during the connect phase when redirects are disabled, and resolved an unsettled-promise hang when an aborted request was combined with compression and maxRedirects: 0. (#10708, #10819, #7149)maxBodyLength / maxContentLength in the fetch adapter, set the User-Agent header to match the HTTP adapter, preserved the original abort reason instead of replacing it with a generic error, and deferred global access so importing the module no longer throws a TypeError in restricted environments. (#10795, #10772, #10806, #7260)cancelToken and AbortSignal listeners on the error, timeout, and abort code paths to prevent leaked subscriptions. (#10787)AxiosError when JSON.parse fails inside dispatchRequest, prevented settle from emitting undefined error codes, and tightened the parseProtocol regex to require a colon in the protocol separator. (#10724, #7276, #10729)CancelToken typings with the ESM build, fixed a compiler error caused by RawAxiosHeaders, and re-exported create from the package index. (#7414, #6389, #6460)unescape() call with a modern UTF-8 encoding implementation. (#7378)utils module and XHR adapter to use ES6 features, and tidied the multipart boundary error message. (#10588, #7419)FormData EPIPE failures, fixed Win32 platform support for the pipe tests, and corrected an incorrect test assumption. (#10820, #10791, #10796)paramsSerializer.encode for strict RFC 3986 query encoding, updated the parseReviver TypeScript definitions and configuration docs for ES2023, added timeout guidance to the README's first async example, and expanded notes around the recent type changes. (#10821, #10782, #10759, #10804)transformRequest input typing change from #10745 after follow-up review. (#10745, #10810)actions/setup-node, the github-actions group, and postcss (in /docs) to their latest versions. (#10785, #10813, #10814)We are thrilled to welcome our new contributors. Thank you for helping improve axios:
This release delivers prototype-pollution hardening for the Node HTTP adapter, adds an opt-in allowedSocketPaths allowlist to mitigate SSRF via Unix d
This release delivers prototype-pollution hardening for the Node HTTP adapter, adds an opt-in allowedSocketPaths allowlist to mitigate SSRF via Unix domain sockets, fixes a keep-alive socket memory leak, and ships supply-chain hardening across CI and security docs.
resolveConfig/mergeConfig/validator paths to read only own properties and use null-prototype config objects, preventing polluted auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser from influencing requests. (#10779)socketPath: Rejects non-string socketPath values and adds an opt-in allowedSocketPaths config option to restrict permitted Unix domain socket paths, returning AxiosError ERR_BAD_OPTION_VALUE on mismatch. (#10777).npmrc with ignore-scripts=true, lockfile lint CI, non-blocking reproducible build diff, scoped CODEOWNERS, expanded SECURITY.md/THREATMODEL.md with provenance verification (npm audit signatures), 60-day resolution policy, and maintainer incident-response runbook. (#10776)allowedSocketPaths Config Option: New request config option (and TypeScript types) to allowlist Unix domain socket paths used by the Node http adapter; backwards compatible when unset. (#10777)error listener tracking the active request via kAxiosSocketListener/kAxiosCurrentReq, eliminating per-request listener accumulation, MaxListenersExceededWarning, and linear heap growth under concurrent or long-running keep-alive workloads (fixes #10780). (#10788)CHANGELOG.md with v1.15.1 release notes. (#10781)This release ships a coordinated set of security hardening fixes across headers, body/redirect limits, multipart handling, and XSRF/prototype-pollutio
This release ships a coordinated set of security hardening fixes across headers, body/redirect limits, multipart handling, and XSRF/prototype-pollution vectors, alongside a broad sweep of bug fixes, test migrations, and threat-model documentation updates.
in checks with hasOwnProperty to prevent authentication bypass via prototype pollution on config objects, with additional regression tests. (#10761, #10760)withXSRFToken Truthy Bypass: Short-circuits on any truthy non-boolean value, so an ambiguous config no longer silently leaks the XSRF token cross-origin. (#10762)maxBodyLength With Zero Redirects: Enforces maxBodyLength even when maxRedirects is set to 0, closing a bypass path for oversized request bodies. (#10753)maxContentLength Bypass: Applies maxContentLength to streamed responses that previously bypassed the cap. (#10754)Location Request Header Type: Adds Location to CommonRequestHeadersList for accurate typing of redirect-aware requests. (#7528)Content-Type when no boundary is present on FormData fetch requests, supports multi-select fields, cancels request.body instead of the source stream on fetch abort, and fixes a recursion bug in form-data serialisation. (#7314, #10676, #10702, #10726)loaded to total for computable upload/download progress events. (#7458)runWhen type with the runtime behaviour in InterceptorManager and makes response header keys case-insensitive. (#7529, #10677)buildFullPath: Uses strict equality in the base/relative URL check. (#7252)AxiosURLSearchParams Regex: Improves the regex used for param serialisation to avoid edge-case mismatches. (#10736)THREATMODEL.md, including Hopper security update, TLS and tag-replay wording, mitigation descriptions, decompression-bomb guidance, and further cleanup. (#10672, #10715, #10718, #10722, #10763, #10765)shouldBypassProxy coverage for wildcard/IPv6/edge cases, documented and tested AxiosError.status, and migrated progressEventReducer tests to Vitest. (#10723, #10725, #10741)CODEOWNERS, switches v1.x releases to an ephemeral release branch, and removes orphaned Bower support. (#10739, #10738, #10746)follow-redirects (1.15.11 → 1.16.0) in root and docs, axios (1.14.0 → 1.15.0) in docs, and a group of 5 development dependencies. (#10717, #10716, #10684, #10709)We are thrilled to welcome our new contributors. Thank you for helping improve axios:
Header Injection: Fixed an unrestricted cloud metadata exfiltration vulnerability via a header injection chain. (__#10660__)
This release delivers two critical security patches, adds runtime support for Deno and Bun, and includes significant CI hardening, documentation improvements, and routine dependency updates.
url.parse() usage has been replaced to address Node.js deprecation warnings. If you are on a recent version of Node.js, this resolves console warnings you may have been seeing. (#10625)no_proxy hostname normalisation bypass that could lead to Server-Side Request Forgery (SSRF). (#10661)zizmor security scanner, pinned action versions, and gated npm publishing with OIDC and environment protection. (#10618, #10619, #10627, #10637, #10666)serialize-javascript, handlebars, picomatch, vite, and denoland/setup-deno to latest versions. Added a 7-day Dependabot cooldown period. (#10574, #10572, #10568, #10663, #10664, #10665, #10669, #10670, #10616)beforeRedirect credential leakage example, clarified withCredentials/withXSRFToken behaviour, HTTP/2 support notes, async/await timeout error handling, header case preservation, and various typo fixes. (#10649, #10624, #7452, #7471, #10654, #10644, #10589)Content-Type casing. (#10573)We are thrilled to welcome our new contributors. Thank you for helping improve Axios:
This release delivers two critical security patches targeting header injection and SSRF via proxy bypass, adds official runtime support for Deno and Bun, and includes significant CI security hardening.
Breaking Changes: None identified in this release.
This release focuses on compatibility fixes, adapter stability improvements, and test/tooling modernisation.
proxy-from-env v2 alignment and main entry compatibility fix).ReadableStream created during request-stream capability probing to prevent async resource leaks. (#7515)proxy-from-env v2 usage. (#7499)main entry regression affecting CJS consumers. (#7532)formidable and refreshed package set to newer versions. (#7533, #10556)We are thrilled to welcome our new contributors. Thank you for helping improve Axios:
Full Changelog: v1.13.6...v1.14.0
This release fixes a security vulnerability in the formidable dependency, resolves a CommonJS compatibility regression, hardens proxy and HTTP/2 handling, and modernises the build and test toolchain.
Breaking Changes: None identified in this release.
This release focuses on platform compatibility, error handling improvements, and code quality maintenance.
Environment Compatibility:
Error Handling:
We are thrilled to welcome our new contributors! Thank you for helping improve the project:
Full Changelog: v1.13.5...v1.13.6
This release adds React Native Blob support, fixes several enumeration and export regressions, and patches FormData detection for WeChat Mini Program environments.
Fix deprecated Buffer constructor usage and README formatting. (PR #7371)
__proto__ key in mergeConfig. (PR #7369)AxiosError could be missing the status field on and after v1.13.3. (PR #7368)__proto__ key in mergeConfig. (PR #7369)Buffer constructor usage and README formatting. (PR #7371)karma-sourcemap-loader from 0.3.8 to 0.4.0. (PR #7360)Full Changelog: https://github.com/axios/axios/compare/v1.13.4...v1.13.5
This release patches a prototype pollution denial-of-service vulnerability, fixes a missing status field regression in AxiosError, adds interceptor ordering control, and introduces URL validation for isAbsoluteURL.
The release addresses issues discovered in v1.13.3 and includes significant CI/CD improvements.
The release addresses issues discovered in v1.13.3 and includes significant CI/CD improvements.
Full Changelog: v1.13.3...v1.13.4
refactor: ci and build (#7340) (8ff6c19)
chore: codegen and some updates to workflows (76cf77b)
None in this release.
None in this release.
Thank you to all contributors who made this release possible! Special thanks to:
Patch release fixing regressions introduced in v1.13.3, including TypeScript export compatibility and CI/build stability.
http2: Use port 443 for HTTPS connections by default.
undefined as a value in AxiosRequestConfig (#5560) (095033c)http: fix 'socket hang up' bug for keep-alive requests when using timeouts;
http: fixed a regression that caused the data stream to be interrupted for responses with non-OK HTTP statuses;
fetch: prevent TypeError when config.env is undefined
fetch: use current global fetch instead of cached one when env fetch is not specified to keep MSW support;
## Release notes: ### Bug Fixes * types: fixed env config types; (#7020) (b5f26b7) ### Contributors to this release - Dmitriy Mozgovoy")
getSetCookie by using 'get' method for caseless access; (#6874) (d4f7df4)fetch-adapter: set correct Content-Type for Node FormData
prevent RangeError when using large Buffers
adapter: pass fetchOptions to fetch function
core: fix the Axios constructor implementation to treat the config argument as optional;
getSetCookie by using 'get' method for caseless access; (#6874) (d4f7df4)buildFullPath: handle allowAbsoluteUrls: false without baseURL
add missing type for allowAbsoluteUrls
allowAbsoluteUrls to buildFullPath in xhr and fetch adapters (#6814) (ec159e5)http-adapter: add allowAbsoluteUrls to path building
utils: move generateString to platform utils to avoid importing crypto module into client builds;
generateString to platform utils to avoid importing crypto module into client builds; (#6789) (36a5a62)generateString to platform utils to avoid importing crypto module into client builds; (#6789) (36a5a62)code relying on the above will now combine the URLs instead of prefer request URL
feat: add config option for allowing absolute URLs
fix: add default value for allowAbsoluteUrls in buildFullPath
fix: typo in flow control when setting allowAbsoluteUrls
examples: application crashed when navigating examples in browser
code relying on the above will now combine the URLs instead of prefer request URL
feat: add config option for allowing absolute URLs
fix: add default value for allowAbsoluteUrls in buildFullPath
fix: typo in flow control when setting allowAbsoluteUrls
Revert "fix(types): export CJS types from ESM (#6218)" (#6729) (c44d2f2), closes #6218 #6729
use URL API instead of DOM to fix a potential vulnerability warning;
globalThis.TextEncoder when available (#6634) (df956d1)fetch: fix stream handling in Safari by fallback to using a stream reader instead of an async iterator;
fetch: fix content length calculation for FormData payload;
adapter: fix undefined reference to hasBrowserEnv
ReferenceError: navigator is not defined for custom environments; (#6567) (fed1a4b)sec: disregard protocol-relative URL to remediate SSRF
adapter: fix progress event emitting;
fetch: enhance fetch API detection;
fetch: fixed ReferenceError issue when TextEncoder is not available in the environment;
core/axios: handle un-writable error stack
fetch: capitalize HTTP method names;
core/axios: handle un-writable error stack
npm i axios@next
## Release notes: ### Features * adapter: add fetch adapter; (#6371) (a3ff99b) ### Contributors to this release - Dmitriy Mozgovoy") - Jay") ### Insta
npm i axios@next
vulnerability: update follow-redirects to 1.15.6
capture async stack only for rejections with native error objects;
fixed missed dispatchBeforeRedirect argument
ci: refactor notify action as a job of publish action;
security: fixed formToJSON prototype pollution vulnerability;
Regular Expression Denial of Service (ReDoS)
withXSRFToken: added withXSRFToken option as a workaround to achieve the old withCredentials behavior;
withCredentials behavior; (#6046) (cff9967)
📢 This PR added 'withXSRFToken' option as a replacement for old withCredentials behaviour.
You should now use withXSRFToken along with withCredential to get the old behavior.
This functionality is considered as a fix.
formdata: fixed content-type header normalization for non-standard browser environments;
📢 This PR added 'withXSRFToken' option as a replacement for old withCredentials behaviour.
You should now use withXSRFToken along with withCredential to get the old behavior.
This functionality is considered as a fix.
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
CSRF: fixed CSRF vulnerability CVE-2023-45857
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
adapters: improved adapters loading logic to have clear error messages;
Content-Type header for FormData in non-browser environments; (#5917) (bc9af51)content-encoding header to handle case-insensitive values (#5890) (#5892) (4c89f25)Content-Type header for FormData in non-browser environments; (#5917) (bc9af51)content-encoding header to handle case-insensitive values (#5890) (#5892) (4c89f25)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
cacheable-lookup integration; (#5836) (b3e327d)unsafe prefix (#5839) (1601f4a)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
multipart/form-data content type for FormData payload on custom client environments; (#5678) (bbb61e7)AxiosHeaderValue type. (#5525) (726f1c8)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
adapter: make adapter loading error more clear by using platform-specific adapters explicitly
cacheable-lookup integration; (#5836) (b3e327d)unsafe prefix (#5839) (1601f4a)formdata: add multipart/form-data content type for FormData payload on custom client environments;
multipart/form-data content type for FormData payload on custom client environments; (#5678) (bbb61e7)AxiosHeaderValue type. (#5525) (726f1c8)types: added transport to RawAxiosRequestConfig
toString method on the target; (#5661) (aa372f7)toString method on the target; (#5661) (aa372f7)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
headers: fixed isValidHeaderName to support full list of allowed characters;
paramsSerializer config; (#5633) (a56c866)paramsSerializer config; (#5633) (a56c866)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
blob: added a check to make sure the Blob class is available in the browser's global scope;
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
formdata: added a check to make sure the FormData class is available in the browser's global scope;
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
http: treat http://localhost as base URL for relative paths to avoid ERR_INVALID_URL error;
ERR_INVALID_URL error; (#5528) (128d56f)ERR_INVALID_URL error; (#5528) (128d56f)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
formdata: add hotfix to use the asynchronous API to compute the content-length header value;
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
Your coding agent can read these notes before it upgrades. Set up the MCP server →