NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #237 most downloaded on npm
Promise based HTTP client for the browser and node.js
Last release 3 days ago
16 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
52 versions withdrawn
withdrawn after publishing
12 years old
145 releases · first in 2014
headers: fixed & optimized clear method;
One column per quarter.
headers: added missed Authorization accessor;
CommonRequestHeadersList & CommonResponseHeadersList types to be private in commonJS; (#5503) (5a3d0a3)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
types: fixed AxiosHeaders to handle spread syntax by making all methods non-enumerable;
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
types: renamed RawAxiosRequestConfig back to AxiosRequestConfig;
RawAxiosRequestConfig back to AxiosRequestConfig; (#5486) (2a71f49)AxiosRequestConfig generic; (#5478) (9bce81b)
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
types: fixed AxiosRequestConfig header interface by refactoring it to RawAxiosRequestConfig;
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
fix(ci): fix release script inputs #5392
feat(exports): export mergeConfig #5151
changed: refactored module exports #5162
changed: refactored module exports #5162
Added custom params serializer support #5113
Added custom params serializer support #5113
Fixed top-level export to keep them in-line with static properties #5109 Stopped including null values to query string. #5108 Restored proxy config backwards compatibility with 0.x #5097 Added back AxiosHeaders in AxiosHeaderValue #5103 Pin CDN install instructions to a specific version #5060 Handling of array values fixed for AxiosHeaders #5085
docs: match badge style, add link to them #5046 chore: fixing comments typo #5054 chore: update issue template #5061 chore: added progress capturing section to the docs; #5084
Fixed broken exports for UMD builds.
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
Fixed broken exports for common js. This fix breaks a prior fix, I will fix both issues ASAP but the commonJS use is more impactful.
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
Fixed missing exports in type definition index.d.ts #5003
⚠️ Critical vulnerability fix. See https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
Replacing deprecated substr() with slice() as substr() is deprecated #4468
Replacing deprecated substr() with slice() as substr() is deprecated #4468
⚠️ Breaking Changes & Deprecations
This release hardens request configuration and proxy handling, adds caller diagnostics and cancellation context, and tightens TypeScript header types.
Full Changelog: v0.33.0...v0.34.0
This release hardens request config handling and form serialisation, adds Node.js 26 coverage for v0.x, and updates the v0.x release workflow.
This release hardens request config handling and form serialisation, adds Node.js 26 coverage for v0.x, and updates the v0.x release workflow.
0.0.0.0 as local for proxy bypass. (#11001)…stricter proxy/cookie/socket handling, and one breaking change to merged config and header object prototypes.
This release backports a comprehensive set of security and hardening fixes from the v1.x branch into v0.x, covering prototype-pollution protections, default error redaction, stricter proxy/cookie/socket handling, and one breaking change to merged config and header object prototypes.
This release backports a broad set of security hardenings from the v1 line — covering prototype-pollution defences, stream size enforcement, XSRF hand
This release backports a broad set of security hardenings from the v1 line — covering prototype-pollution defences, stream size enforcement, XSRF handling, URL null-byte encoding, and bounded FormData recursion — and drops committed dist/ artefacts along with Bower support.
dist/ Removed: dist/ bundles are no longer committed to the repo, and bower.json plus the Grunt package2bower task have been removed. CI still builds bundles before publish, so npm/yarn/pnpm consumers are unaffected; installs via Bower or directly from the git tree must migrate to npm or a CDN. (#10747)isFormData to reject plain/null-prototype objects and require append, and guarded the Node HTTP adapter so data.getHeaders() is only merged when it is not inherited from Object.prototype. Blocks injected headers via polluted getHeaders. (#10750)mergeConfig, defaults resolution, and the HTTP adapter now uses own-property checks for transport, env, Blob, formSerializer, and transforms arrays, and merged configs are returned as null-prototype objects. Prevents hijacking of the request flow through polluted prototypes. (#10752)maxDepth (default 100, Infinity disables) to toFormData and params serialisation, throwing AxiosError with code ERR_FORM_DATA_DEPTH_EXCEEDED when exceeded. Circular-reference detection is preserved. (#10728)%00 → null-byte substitution from AxiosURLSearchParams.encode so %00 is preserved as-is. Other encoding behaviour (including %20 → +) unchanged. (#10737)v0.x: maxContentLength enforcement for responseType: 'stream' via a guarded transform with deferred piping, maxBodyLength enforcement for streamed uploads on native http/https with maxRedirects: 0, and stricter withXSRFToken handling so only own boolean true enables cross-origin XSRF headers. (#10764).github/CODEOWNERS with * @jasonsaayman to set a default reviewer for all paths. (#10740)This release backports security fixes from v1.x, hardens the CI/CD supply chain with OIDC publishing and zizmor scanning, resolves TypeScript typing i…
This release backports security fixes from v1.x, hardens the CI/CD supply chain with OIDC publishing and zizmor scanning, resolves TypeScript typing issues in AxiosInstance, and fixes a performance regression in isEmptyObject().
Header Injection & Proxy Bypass: Backports v1 security hardening — sanitizes outgoing header values to strip invalid bytes, CRLF sequences, and boundary whitespace (including array values); adds proper NO_PROXY/no_proxy enforcement covering wildcards, explicit ports, loopback aliases (localhost, 127.0.0.1, ::1), bracketed IPv6, and trailing-dot hostnames. Proxy bypass is now checked before the proxy URL is parsed, and parsed.host is used for correct port and IPv6 handling. (#10688)
CI Security: SHA-pins all actions and disables credential persistence in v0.x CI, introduces zizmor security scanning with SARIF upload to code scanning, adds an OIDC Trusted Publishing workflow with npm provenance attestations, and gates all publishes behind a required npm-publish GitHub Environment with configurable reviewer protections. (#10638, #10639, #10667)
TypeScript — AxiosInstance Return Types: Fixes return types in AxiosInstance methods to correctly resolve to Promise<R> (matching AxiosPromise<T> semantics), and corrects the generic call signature so TypeScript properly enforces the response data type. TypeScript-only changes; no runtime impact. (#6253, #7328)
Performance: Fixes a performance regression in isEmptyObject() that caused excessive computation when the argument was a large string. (#6484)
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
This is a critical security maintenance release for the v0.x branch. It addresses a high-priority vulnerability involving prototype pollution that cou…
This is a critical security maintenance release for the v0.x branch. It addresses a high-priority vulnerability involving prototype pollution that could lead to a Denial of Service (DoS).
Recommendation: All users currently on the 0.x release line should upgrade to this version immediately to ensure environment stability.
Configuration Merging Behavior:
As part of the security fix, Axios now restricts the merging of the proto key within configuration objects. If your codebase relies on unconventional deep-merging patterns that target the object prototype via Axios config, those operations will now be blocked. This is a necessary change to prevent prototype pollution.
Full Changelog: v0.30.2...v0.30.3
Backport maxContentLength vulnerability fix to v0.x by @FeBe95 in https://github.com/axios/axios/pull/7034
maxContentLength vulnerability fix to v0.x by @FeBe95 in https://github.com/axios/axios/pull/7034Full Changelog: https://github.com/axios/axios/compare/v0.30.1...v0.30.2
chore(deps): bump form-data from 4.0.0 to 4.0.4 for v0.x by @wolandec in https://github.com/axios/axios/pull/6978
Full Changelog: https://github.com/axios/axios/compare/v0.30.0...v0.30.1
fix: backport allowAbsoluteUrls vulnerability fix to v0.x by @thatguyinabeanie in https://github.com/axios/axios/pull/6829
Full Changelog: https://github.com/axios/axios/compare/v0.29.0...v0.30.0
fix(backport): backport security fixes in commits #6167 and #6163 to v0.x by @Sean-Powell in https://github.com/axios/axios/pull/6402
fix(backport): custom params serializer support
req is not defined (#6307)fix(security): fixed CVE-2023-45857 by backporting withXSRFToken option to v0.x
withXSRFToken option to v0.x (#6091)axios.formToJSON method (#4735)url-encoded-form serializer to respect the formSerializer config (#4721)string[] to AxiosRequestHeaders type (#4322)AxiosError stack capturing; (#4718)AxiosError status code type; (#4717)blob to the list of protocols supported by the browser (#4678)Fixed FormData posting in browser environment by reverting #3785
Removed import of url module in browser build due to huge size overhead and builds being broken
New toFormData helper function that allows the implementor to pass an object and allow axios to convert it to FormData
Content-Type request header when passing FormData (#3785)transformRequest and toFormData (#4470)Refactored project file structure to avoid circular imports
Update follow-redirects dependency due to Vulnerability
Fixing maxBodyLength enforcement
boolean and number types (#4144)undefined (#3153)Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Revert: change type of AxiosResponse to any, please read lengthy discussion here: (#4141) pull request:
Distinguish request and response data types
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Caseless header comparing in HTTP adapter
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Fixing JSON transform when data is stringified. Providing backward compatibility and complying to the JSON RFC standard
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Fixing response interceptor not being called when request interceptor is attached
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Adding security fix for ReDoS vulnerability
AUTH_TOKEN with multiple domain endpoints (#3539)Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Protocol not parsed when setting proxy config from env vars
AxiosError (#2949)socket http test (#3364)Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Fixing requestHeaders.Authorization
Huge thanks to everyone who contributed to this release via code (authors listed below) or via reviews and triaging on GitHub:
Release of 0.20.0-pre as a full release with no other changes.
Release of 0.20.0-pre as a full release with no other changes.
Nothing published for this version
Remove unnecessary XSS check (#2679) (see (#2646) for discussion)
Fixing Vulnerability A Fortify Scan finds a critical Cross-Site Scrip…
config.method after mergeConfig for Axios.prototype.request (#2383)Unzip response body only for statuses != 204 (#1129) - drawski
#, because client cut everything after #getUri signature to TypeScript definition. (#1736) - Alexander Trauzzi.then to .finally in example code (#2090) - Omar CairesponseType: 'blob' doesn't actually work in Node (when I tried using it, response.data was a string, not a Blob, since Node doesn't have Blobs), so this clarifies that this option should only be used in the browserFix Removes usage of deprecated Buffer constructor. (#1555, #1622)
NOTE: This is a beta version of this release. There may be functionality that is broken in certain browsers, though we suspect that builds are hanging and not erroring. See https://saucelabs.com/u/axios for the most up-to-date information.
false flag isStandardBrowserEnv for NativescriptDestroy stream on exceeding maxContentLength (fixes #1098) (#1485) - Gadzhi Gadzhiev
Adding support for UNIX Sockets when running with Node.js
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →