Axios 0.24.x and 0.27.x Vulnerabilities: CVEs Upstream Will Not Patch
Up to 21 CVEs affect Axios 0.24.x and 0.27.x with no upstream fix. Here's each one, where it was fixed upstream, and which NES for Axios already patches.

Axios 0.24.x and 0.27.x have no upstream fix for any of the up to 21 Axios security advisories that apply to them, and there never will be one on those lines. Axios 0.24.0 (October 2021) and 0.27.2 (April 2022) are the final releases of their minor lines: the Axios project resolves 0.x vulnerabilities only in the newest 0.x release, currently 0.34.0.
On September 25, 2026, HeroDevs launched Never-Ending Support (NES) for Axios in an official partnership with the Axios project, and NES for Axios already resolves 19 of those CVEs as a drop-in npm package replacement.
Axios 0.24.x and 0.27.x CVEs at a Glance
If you can move to the current Axios 1.x release (1.20.0 as of September 2026), do. That resolves everything below.
Pinned to 0.24.x: 19 CVEs apply, including two rated Critical by NVD. NES for Axios 0.24.x fixes 19 today, including CVE-2026-42043 (NVD 10.0 Critical; GitHub CNA 7.2 High) and CVE-2025-62718 (NVD 9.9; GitHub 6.3 Medium).
Pinned to 0.27.x: The same 19 apply, plus two more that exist only in code added after 0.24, for 21 total.
Why are so many apps still on Axios 0.x
Despite its massive footprint, averaging over 85 million weekly npm downloads and appearing in the dependency trees of more than 174,000 published packages, a significant portion of production code remains stuck on Axios 0.x, even though Axios 1.0 was released in October 2022.
This lag is rarely intentional. Applications usually remain on legacy versions due to three main factors:
1. Transitive Pinning
Many applications do not import Axios directly; instead, third-party libraries, such as Cloud SDKs, observability agents, or internal CLI tools, depend on it behind the scenes. If these parent packages specified rigid version ranges (such as axios: ^0.27.0) and have not issued an update, your application will pull in Axios 0.27.2 automatically. You didn't explicitly choose a legacy version; your dependencies inherited it for you.
2. Breaking Behavioral Changes in Axios 1.0
Upgrading from 0.x to 1.x isn't a drop-in swap. The 1.0 release introduced several breaking changes:
- Error Handling: Changes to how request and response errors are caught or structured.
- Header Normalization: Alterations in how HTTP headers are case-formatted and processed.
- Module Resolution: Adjustments to how Node.js and bundlers load the library's CommonJS versus ES Module formats.
Code written to rely on 0.x behaviors will often break when exposed to these 1.x updates.
3. End-of-Life Node.js Runtimes
In many legacy enterprise stacks, updating Axios requires updating the Node.js runtime itself, which may be running an End-of-Life (EOL) version. When the underlying Node.js version is no longer maintained or compatible with modern packages, upgrading application-level dependencies becomes impossible without first modernizing the entire runtime environment.
Axios publishes no LTS schedule and no per-version maintenance windows. Upstream 0.x fixes land only in the newest 0.x release. Axios 0.24.0 has never received a 0.24.1, and 0.27.2 has never received a 0.27.3. The only upstream remediation for either line is a jump to 0.34.0 (ten minor versions past 0.24.0, seven past 0.27.2) or a migration to 1.x. Either carries the regression risk of any major dependency change.
The 19 CVEs NES for Axios 0.24.x already resolves
NES for Axios 0.24.x, released September 9, 2026, resolves the following. Every one also affects Axios 0.27.x.
NVD column shows NIST's primary CVSS 3.1 score; 'No NVD primary score' means NIST has not yet scored the CVE."
"Upstream 0.x fix" is the earliest upstream release carrying the fix. None of those releases is on the 0.24.x or 0.27.x line.
Two more CVEs upstream will not fix on Axios 0.27.x
These CVE fixes will be available next on NES for Axios 0.27.x distribution.
Are Axios 0.x CVEs being exploited?
None of the 21 CVEs appear in the CISA Known Exploited Vulnerabilities catalog (catalog version 2026.09.27), and the upstream advisories report no active exploitation.
The barrier to exploitation is low, though. Several GitHub advisories, including those for CVE-2025-62718, CVE-2026-25639, and CVE-2026-42039, publish short proof-of-concept snippets, and the fixed releases make the vulnerable code paths easy to diff.
Mitigation guidance
Switching to NES for Axios 0.24.x is a registry change plus a package.json edit, per the installation guide:
{
"dependencies": {
"axios": "npm:@neverendingsupport/axios@0.24.0-axios-0.24.3"
},
"overrides": {
"axios": "npm:@neverendingsupport/axios@0.24.0-axios-0.24.3"
}}
@neverendingsupport:registry=https://registry.nes.herodevs.com/npm/pkg
///registry.nes.herodevs.com/npm/pkg/:_authToken=<NES_ACCESS_TOKEN>
Most applications need no code changes. NES for Axios 0.24.2 does document four security-driven behavior changes. The one most likely to matter: cross-origin requests with withCredentials: true no longer send the XSRF token unless you also set with XSRFToken: true. Review the 0.24.x release notes before rolling out.
Taking action
If you can move to the latest Axios 0.x or Axios 1.x, that is the right destination. If you cannot, the question to answer this sprint is which 0.x version your application actually resolves to, including every transitive copy, because upstream has already decided it will not fix 0.24.x or 0.27.x. Every new Axios advisory in 2026 has landed on 0.x only in the newest release, and pinned lines accumulate exposure with each one.
HeroDevs partners directly with the Axios project, and part of what NES for Axios earns funds the project itself.
See NES for Axios for coverage details, or talk to our team about scoping the Axios 0.x versions in your dependency tree.
Resources
View All Articles

%20for%20Axios.webp)
