Legacy Axios versions secure for as long as you need.

Supported Versions: 0.24.x, 0.27.x, 0.33.x, and more

Never-Ending Support for Axios gives your security team, your engineers, and your leadership back something they lost at EOL: the power to control your own security posture, your own timeline, and where your business focuses its attention.

TRUSTED BY ENTERPRISE

Google logoMicrosoft logoFinra logoBank Santander Logo
Hitachi LogoWorkday logoDropbox logo

Security, compliance, and continuity -- solved together

With our secure drop-in replacement for end-of-life versions of Axios, your scanners stop flagging CVEs in end-of-life Axios versions for good.

Security

A new release ships each time an Axios CVE is found, validated, and fixed on versions the project no longer patches, developed by engineers with core-maintainer expertise in this stack.

SLA-backed patch delivery tied to severity

HeroDevs is an authorized CVE Numbering Authority discloses discovered vulnerabilities.

Compliance

Once installed, scanners stop flagging Axios CVEs because the library is actively patched and commercially supported, turning open audit findings into closed ones.

SOC 2, PCI DSS, HIPAA, FedRAMP, ISO 27001, NIS2 and more

Documented patch history for auditors

Business continuity

A true drop-in: same package interface, same npm and CI/CD workflow, no application code changes. The parent dependency or runtime that pinned Axios can be addressed in the right order.

Months or years of runway to migrate right

A fraction of migration cost or the cost of a breach.

Every patch we ship has a published CVE entry

HeroDevs is an authorized CVE Numbering Authority (CNA), empowered by the CVE Program to discover and assign CVE IDs to security vulnerabilities discovered by HeroDevs.

If you're running EOL Axios today, your applications are exposed to the vulnerabilities below. NES for Axios fixes them in minutes.

11 CVEs remediated — and counting
Severity
ID
Category
Version(s) Affected
Published Date
Medium
Cross-site Request Forgery
<1.6.0; <0.28.0
Sep 23, 2026
Medium
Prototype Pollution
>=1.0.0, <1.16.0; <0.32.0
Sep 23, 2026
High
Server-Side Request Forgery
>=1.0.0, <1.16.0; <0.32.0
Sep 23, 2026
High
Regular Expression Denial of Service
>=1.0.0, <1.16.0; <0.32.0
Sep 23, 2026
Medium
Allocation of Resources Without Limits or Throttling
>=1.0.0, <1.15.1; <0.31.1
Sep 23, 2026
Medium
Prototype Pollution
>=0.8.0, <0.33.0
Sep 23, 2026
High
Server-Side Request Forgery
>=1.0.0 <1.15.1; <0.31.1
Sep 23, 2026
Medium
Authorization Bypass
Prototype Pollution
>=1.0.0 <1.15.1; <0.31.1
Sep 23, 2026
Medium
Allocation of Resources Without Limits or Throttling
>=1.0.0 <1.15.1; <0.31.1
Sep 23, 2026
Medium
Server-Side Request Forgery
>=1.0.0 <1.15.1; <0.31.1
Sep 18, 2026
High
Server-Side Request Forgery
<=1.7.9; <=0.29.0
Sep 18, 2026

One Registry Change. No Code Change.

# point the HeroDevs scope at NES
npm config set @herodevs:registry \
  https://registry.herodevs.com/npm/

# install the drop-in replacement
npm install @herodevs/axios@0.31.x

# imports and call sites stay as written
1

Substitute the Axios dependencies in your package.json with the following

2

Create an .npmrc file with the following

3

Install your dependencies

A defensible answer for every standard, framework, or regulation.

Legacy software  and unofficial community support undermines patch-management expectations across regulations worldwide. NES gives you a maintained, vendor-backed library with committed SLAs and a documented patch history to show auditors and regulators.

PCI DSS

US

Req. 6.3.3 requires known vulnerabilities to be patched, including a 30-day SLA for critical issues. Legacy Axios with no patch means immediate non-compliance — NES restores the patch path.

HIPAA

US

Unsupported components make it hard to show reasonable safeguards for systems handling ePHI. NES provides active maintenance and documented risk reduction.

SOC 2

Global

Trust Services Criteria expect timely vulnerability remediation and patch management. Legacy components with no security patches translate to failing certification.

FedRAMP

US

Baselines build on NIST SI-2, requiring flaws to be corrected and security updates installed within defined timeframes. Unpatched legacy software in government cloud does not meet compliance.

DORA

EU

Treats legacy software as a resilience flaw for financial ICT assets. NES sustains a documented patch-management program for critical systems.

NIS2 Directive

EU

Article 21 covers patching, vulnerability and supply-chain management. Legacy unpatched software is effectively non-compliant where it creates risk.

GDPR

EU

Article 32 expects "state of the art" technical measures. Running unsupported legacy software is difficult to defend after a breach — NES keeps the dependency maintained.

NIST CSF 2.0

US

Control PR.PS-02 requires organizations to actively maintain or remove vulnerable software based on risk. NES enables compliance without forced upgrade or removal

Cyber Resilience Act

US

Requires vulnerabilities in products and their components to be handled effectively during the support period. NES keeps front-end components covered.

ISO/IEC 27001:2022

Global

Vulnerability Management and Configuration Management controls require identifying technical vulnerabilities and keeping software within secure standards. NES restores control posture with patch availability for EOL software.

CIS Controls AU

control 7 (Continuous Vulnerability Management) and Control 2 (Software Asset Inventory) treat software that no longer receives security updates as inherently vulnerable. NES keep software patched and auditable.

Commercial Contracts

Many organizations are contractually prohibited from shipping unsupported software. NES provides the vendor-backed answer your own polices require.

We Partner with Axios

HeroDevs partners directly with the Axios maintainers and funds the project’s ongoing sustainability and growth.

Vue LogoAngular LogoDrupal Association logoNuxt LogoProtractor logoAxios logo
User icon with computer

We Give Back to Open Source

Open source maintainers do critical work, but rarely get paid for it.

HeroDevs is putting $20 million toward changing that — funding the creators and projects that keep the ecosystem running, with grants from $2,500 to $250,000.

We’ve written patches for unmaintained codebases, tracked down vulnerabilities where no one else was looking, and kept critical systems running safely without rushed rewrites. This fund builds on that work, so maintainers can keep doing what they do best.

Frequently Asked Questions

Axios has never declared end-of-life. Is it actually unsupported?
Which Axios versions does NES for Axios cover?
Does this replace moving to the supported 1.x line?
What happens when a new vulnerability affects a covered version?
How is it installed?
What evidence do auditors and security reviewers receive?

Contact Us

Got questions about Never-Ending Support for your open-source library? We're here to help!

Discover how HeroDevs NES Products can keep your systems secure and compliant.

Learn how our solutions can deliver value to your organization.

Get detailed pricing information tailored to your needs.

Google logoLilly logoAbbott logoBox logoEG logoHitachi logoDropbox logoNHS logoWorkday logoFinra logoMicrosoft logoSantander logo
Talk to an Expert

By submitting the form I acknowledge receipt of our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.