What changed in Axios from 0 to 1
9 releases numbered after v0.33.0 up to and including v1.20.0, stable releases only. v0.33.0 and v1.20.0 are the newest stable releases of 0 and 1 we track; this page follows them as new ones ship.
- 1 mentions breaking changes
- 2 remove or deprecate something
111 changes across 9 releases
- Add RFC 9110 status-code aliases ContentTooLarge (413) and UnprocessableContent (422)
- Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors, adapters, and serializers
- Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing
- Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status code and matching ESM/CJS declarations
- Add transitional.validateStatusUndefinedResolves option so applications can opt in to treating validateStatus: undefined like the option was omitted, while validateStatus: null remains the explicit way to accept every status
- Add Node HTTP adapter support for zstd response decompression, with transitional.advertiseZstdAcceptEncoding controlling whether zstd is advertised in Accept-Encoding
- Support for the QUERY HTTP method across adapters and type definitions
- ECONNREFUSED error constant exposed on AxiosError for matching connection-refused failures
- Export the internal encode helper from buildURL for userland param serializers
- Add allowedSocketPaths config option to allowlist Unix domain socket paths used by the Node http adapter
- Add initial scaffold for AI-assisted translations of the documentation site
- Add `Location` to `CommonRequestHeadersList` for accurate typing of redirect-aware requests
- Documented sensitive headers and status transition behaviour
- Replaced the array-based cycle tracker in toJSONObject with a WeakSet, improving performance and memory behaviour on large nested structures
- Refactored composeSignals to use a clearer early-return structure, simplifying the cancellation/abort composition path
- Bumped @commitlint/cli from 20.5.0 to 20.5.2
- Proxy requests now preserve user-supplied Host headers
- Basic auth credentials embedded in URLs are now URL-decoded
- parseProtocol now strictly requires a colon in the protocol separator
- Replaced deprecated unescape() with modern UTF-8 encoding for non-ASCII URL handling
- Prevent unbounded handler-array growth by trimming trailing ejected interceptors
- Keep interceptor operations safe when the public handlers field is nullish
- Prevent custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError
- Make navigation-canceled XHR requests reject with ECONNABORTED instead of resolving with status 0
- Flush successful XHR downloads' final progress callback during the live loadend dispatch
- Remove request-context retention from per-socket error listeners to prevent completed response data from being pinned for the lifetime of pooled keep-alive sockets
- Prevent structural method-header buckets from leaking into outgoing headers
- Standardize invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE
- Correct the timeoutErrorMessage merge strategy
- Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys
- Removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills
- Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching
- Honored * entries within comma- or space-separated bypass lists in NO_PROXY matching
- Propagated already-aborted input signals immediately when composing abort signals
- Preserved empty first values for duplicate singleton headers
- Made AxiosHeaders#getSetCookie() consistently return arrays for present values
- Included normalized, safely redacted offending URLs in malformed-protocol errors
- Removed repeated trailing slashes when combining base URLs
- Clamped malformed negative progress values to zero
- Ensured final Node.js download progress events are delivered before streamed responses close
- Serialized Set values as arrays in JSON-compatible snapshots
- Synthesized useful AxiosError messages from otherwise-empty AggregateError instances
- Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters
- Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully
- Made AxiosError#cause non-enumerable to prevent circular JSON serialisation failures when errors include nested causes
- Guarded socket.setKeepAlive for proxy agent streams in Node HTTP adapter
- Accepted path-only URLs when socketPath is configured in Node HTTP adapter
- Deferred environment proxy handling to Node in HTTP adapter
- Explicitly passed maxBodyLength through to follow-redirects in Node HTTP adapter
- Fixed runtime crashes and type definition mismatches in runtime and type correctness
- Fixed incorrect error handling paths
- Switched AxiosURLSearchParams encoder callback to an arrow function so encoder.call(this) receives the AxiosURLSearchParams instance correctly
- Restore Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and align the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth
- Preserve user httpsAgent TLS options when tunneling HTTPS requests through HTTP CONNECT proxies
- Clear default Content-Type for React Native FormData so multipart boundaries can be generated correctly
- Silently skip empty or whitespace-only header names instead of throwing, matching parsed-header behavior and avoiding React Native response crashes
- Preserve enumerable symbol keys when cloning plain request data through axios merge logic
- Convert resolveConfig from an arrow default export to a named function export to avoid webpack and Babel transform interop failures
- Correct AxiosHeaders.toJSON() return types and update CommonJS isCancel typings to narrow to CanceledError<T>
- Avoid emitting a null Authorization header from the GitHub build helper when GITHUB_TOKEN is unset
- Updated the fromDataURI regex to match RFC 2397 more strictly, fixing edge cases in data: URL handling
- Preserved Unicode header values when running through request interceptors, so non-ASCII header content is no longer corrupted before dispatch
- Guarded against malformed ProgressEvent payloads emitted by some environments during XHR upload, preventing crashes when loaded / total are missing or invalid
- Fixed an unexpected token error caused by syntax in the fetch adapter that Webpack 4 could not parse, restoring compatibility for legacy bundler users
- Made parseReviver context.source optional in the type definitions to align with the ES2023 specification
- HTTP adapter cleared stale headers when a redirect targets a no-proxy host
- HTTP adapter fixed the redirect listener chain to prevent stacking across hops
- HTTP adapter restored the missing requestDetails argument on beforeRedirect
- HTTP adapter preserved partial response object on AxiosError when a stream is aborted after headers arrive
- HTTP adapter honoured the timeout option during the connect phase when redirects are disabled
- HTTP adapter resolved an unsettled-promise hang when an aborted request was combined with compression and maxRedirects: 0
- Fetch adapter set the User-Agent header to match the HTTP adapter
- Fetch adapter preserved the original abort reason instead of replacing it with a generic error
- Fetch adapter deferred global access so importing the module no longer throws a TypeError in restricted environments
- XHR adapter unsubscribed cancelToken and AbortSignal listeners on error, timeout, and abort code paths to prevent leaked subscriptions
- Attached the parsed response to AxiosError when JSON.parse fails inside dispatchRequest
- Install a single per-socket error listener tracking the active request via kAxiosSocketListener and kAxiosCurrentReq, eliminating per-request listener accumulation and linear heap growth under concurrent or long-running keep-alive workloads
- Remove `Content-Type` when no boundary is present on `FormData` fetch requests
- Support multi-select fields in FormData handling
- Cancel `request.body` instead of the source stream on fetch abort
- Fix recursion bug in form-data serialisation
- Handle socket-only request errors without leaking keep-alive listeners in HTTP adapter
- Clamp `loaded` to `total` for computable upload/download progress events
- Align `runWhen` type with the runtime behaviour in `InterceptorManager`
- Make response header keys case-insensitive
- Use strict equality in the `buildFullPath` base/relative URL check
- Improve the regex used for `AxiosURLSearchParams` param serialisation to avoid edge-case mismatches
- Parse out header/config values instead of throwing on malformed input
- Reverted support for passing a URL object as config.url due to regressions; this support will be reintroduced in a later release once the underlying issues are addressed
- Deprecate PayloadTooLarge and UnprocessableEntity status-code aliases in favor of ContentTooLarge and UnprocessableContent
- Harden behavioral configuration reads against shared and foreign prototype pollution and normalize unsafe interceptor replacement objects
- Clarify Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection
- Raised the form-data dependency floor to ^4.0.6 to prevent fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx
- Add Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects to prevent custom auth headers such as API keys from leaking to another origin
- Reject malformed http: and https: URLs that omit // with ERR_INVALID_URL, and tighten prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and local NO_PROXY matching
- Guard socketPath, params, and paramsSerializer reads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths
- Switch the publish workflow to npm staged publishing for safer, auditable package releases with provenance
- Hardened formDataToJSON against prototype pollution by walking own properties only, so attacker-controlled keys inherited from a poisoned prototype cannot propagate through deserialization
- Fixed an issue where HTTPS request data could be transmitted in cleartext to an HTTP proxy under certain configurations
- Removed all GitHub Actions caches as a defence-in-depth measure against cache poisoning vectors in the build pipeline
- Fetch adapter now enforces maxBodyLength and maxContentLength limits
- Hardened the Node HTTP adapter and resolveConfig/mergeConfig/validator paths to read only own properties and use null-prototype config objects, preventing polluted auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser from influencing requests
- Reject non-string socketPath values and add an opt-in allowedSocketPaths config option to restrict permitted Unix domain socket paths, returning AxiosError ERR_BAD_OPTION_VALUE on mismatch
- Added .npmrc with ignore-scripts=true, lockfile lint CI, non-blocking reproducible build diff, scoped CODEOWNERS, expanded SECURITY.md and THREATMODEL.md with provenance verification, 60-day resolution policy, and maintainer incident-response runbook
- Tightened validation and sanitisation across request header construction to close the header-injection attack surface
- Correctly strip CR/LF from multipart header values to prevent injection via field names and filenames
- Replace unsafe `in` checks with `hasOwnProperty` to prevent authentication bypass via prototype pollution on config objects
- Short-circuit `withXSRFToken` on any truthy non-boolean value to prevent silent leakage of XSRF token cross-origin
- Enforce `maxBodyLength` even when `maxRedirects` is set to 0
- Apply `maxContentLength` to streamed responses that previously bypassed the cap
- Complete an earlier incomplete CVE fix to fully close the regression window
Original release notes, newest first
The list above is our reading of these notes; the originals from Axios are here, one fold per release.
v1.20.0
v1.20.0 — August 19, 2026
This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.
⚠️ Breaking Changes & Deprecations
- HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)
🔒 Security Fixes
- Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)
🐛 Bug Fixes
- Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
- Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
- XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
- Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
- Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)
🔧 Maintenance & Chores
- Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
- Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
- Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
- CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @yens1 (#11109)
- @Sasireddy001 (#11113)
- @ari-token-security (#11094)
- @timothyokooboh (#11097)
- @gi9439041-png (#11119)
- @Hashim1999164 (#11082)
- @v-dev-cl (#11091)
- @r0h1tb (#11118)
- @ostapondo (#11121)
Full Changelog (https://github.com/axios/axios/compare/v1.19.0...v1.20.0)
v1.19.0
v1.19.0 - July 22, 2026
This release raises the form-data security floor, adds configuration and type-system capabilities, and fixes NO_PROXY matching, interceptor errors, progress reporting, and serialization edge cases.
🔒 Security Fixes
- Multipart Form Data: Raised the form-data dependency floor to ^4.0.6, preventing fresh installations from resolving versions affected by the CRLF injection vulnerability GHSA-hmw2-7cc7-3qxx (https://github.com/advisories/GHSA-hmw2-7cc7-3qxx). (#11028)
🚀 New Features
- Configuration Extensibility: Preserved own-enumerable symbol-keyed fields through mergeConfig and added a generic params type across public TypeScript declarations, responses, errors, adapters, and serializers. (#11043, #11081)
- Header Parameter Parsing: Added the opt-in AxiosHeaders.parseParameters() parser for quote-aware, RFC-style HTTP parameter parsing while preserving legacy parsing behavior. (#11051)
- HTTP Status Codes: Added the missing Cloudflare 520 WebServerReturnsAnUnknownError status and matching ESM/CJS declarations. (#11067)
🐛 Bug Fixes
- Form Data Conversion: Limited formDataToJSON path splitting to dot and bracket notation, preserving literal punctuation in keys, and removed browser-facing Buffer.from usage from toFormData to avoid unnecessary polyfills. (#11006, #11018)
- Proxy Bypass: Canonicalized IPv4 shorthand, octal, and hexadecimal forms during NO_PROXY matching and honored * entries within comma- or space-separated bypass lists. (#11029, #11053)
- Cancellation: Propagated already-aborted input signals immediately when composing abort signals. (#11035)
- Header Handling: Preserved empty first values for duplicate singleton headers and made AxiosHeaders#getSetCookie() consistently return arrays for present values. (#11036, #11037)
- URL Handling: Included normalized, safely redacted offending URLs in malformed-protocol errors and removed repeated trailing slashes when combining base URLs. (#11024, #11038)
- Progress Events: Clamped malformed negative progress values to zero and ensured final Node.js download progress events are delivered before streamed responses close. (#11039, #11040)
- Error and JSON Serialization: Serialized Set values as arrays in JSON-compatible snapshots and synthesized useful AxiosError messages from otherwise-empty AggregateError instances. (#11044, #11059)
- Content-Length Enforcement: Corrected base64 data: URL size estimation so maxContentLength is enforced consistently by the HTTP and Fetch adapters. (#11061)
- Synchronous Interceptors: Prevented requests from being dispatched after synchronous request interceptors fail unless their paired rejection handler resolves successfully. (#11071)
🔧 Maintenance & Chores
- Dependencies: Updated development and test tooling, the docs fixture's Axios version, and GitHub Actions integrations including Checkout, Setup Node, Setup Deno, and Zizmor. (#11031, #11055, #11056, #11058, #11079, #11080, #11088, #11089, #11090)
- Build Outputs: Limited sourcemap generation to published minified bundles, removing broken map references from non-minified builds. (#11054)
- Form Data Internals: Centralized FormData header handling and made the Node.js adapter tolerate getHeaders() returning undefined under the content-only policy. (#11062)
- Developer Experience: Ignored common local AI-tooling directories and fixed a constant-reassignment crash when the development sandbox serves its root path. (#11032, #11073)
- Documentation: Updated sponsor information, clarified that baseURL is not a path-security boundary, scoped provenance claims to attested releases, and corrected the configuration-defaults documentation. (#11041, #11068, #11076, #11078)
- Publishing: Simplified v1 publishing to use the npm version bundled with Node.js 26 and updated package metadata for the 1.19.0 release. (#11083, #11095)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve Axios:
- @afonsojramos (#11028)
- @MahinAnowar (#11006)
- @yassertawfik4 (#11024)
- @AnandSundar (#11029)
- @lin-hongkuan (#11035)
- @Wali007-lab (#11054)
- @magicdawn (#11043)
- @andrewkernel (#11053)
- @Sagargupta16 (#11059)
- @Rpaudel379 (#11078)
- @kobihikri (#11076)
- @spokodev (#11061)
- @shaedrich (#11081)
- @QodeXcli (#11062)
- @akahoshi1421 (#11067)
- @TheHonoredOne914 (#11071)
- @Ahsan1Murtaza (#11073)
Full Changelog (https://github.com/axios/axios/compare/v1.18.1...v1.19.0)
v1.18.1
v1.18.1 — June 21, 2026
This release focuses on Node HTTP adapter fixes, safer AxiosError serialisation, runtime/type correctness fixes, documentation updates, and dependency maintenance.
🐛 Bug Fixes
- AxiosError Serialisation: Made AxiosError#cause non-enumerable to prevent circular JSON serialisation failures when errors include nested causes. (#10913)
- Node HTTP Adapter: Guarded socket.setKeepAlive for proxy agent streams, accepted path-only URLs when socketPath is configured, deferred environment proxy handling to Node, and explicitly passed maxBodyLength through to follow-redirects. (#10917, #10930, #10942, #10993)
- Runtime and Type Correctness: Fixed several runtime crashes, type definition mismatches, and incorrect error handling paths. (#10959, #11021)
- AxiosURLSearchParams: Switched the encoder callback to an arrow function so
encoder.call(this)receives theAxiosURLSearchParamsinstance correctly. (#11019)
🔧 Maintenance & Chores
-
Documentation: Documented sensitive headers and status transition behaviour, prepared cleaned-up docs, added Deno install instructions, and clarified that request data is request-specific (#11007, #11010, #11023, #11025)
-
Dependencies: Bumped vite, rollup, form-data, js-yaml, and multer across the root project, docs, smoke tests, and module test workspaces. (#11011, #11012, #11013, #11014, #11015, #11016, #11017, #11026)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @webdevelopersrinu (#10913)
- @sijie-Z (#10993)
- @bartlomieju (#11023)
- @JSap0914 (#11019)
v1.18.0
v1.18.0 — June 13, 2026
This release hardens redirect and URL handling, improves the validateStatus configuration semantics, and includes updates to documentation, dependencies, and release metadata.
🔒 Security Fixes
-
Redirect Header Safety: Added Node HTTP adapter support for stripping caller-specified sensitive headers on cross-origin redirects, helping prevent custom auth headers such as API keys from leaking to another origin. (#10892)
-
URL And Request Hardening: Rejects malformed
http:andhttps:URLs that omit//withERR_INVALID_URL, while tightening prototype-pollution-safe config reads, stream size limits, FormData depth handling, data URL sizing, and localNO_PROXYmatching. (#11000)
🐛 Bug Fixes
- Status Validation: Added
transitional.validateStatusUndefinedResolvesso applications can opt in to treatingvalidateStatus: undefinedlike the option was omitted, whilevalidateStatus: nullremains the explicit way to accept every status. (#10899)
🔧 Maintenance & Chores
-
Documentation: Published the v1.17.0 release notes, fixed a changelog typo, clarified the package update PR policy, and marked the
proxyrequest config as Node.js-only in the advanced docs. (#10984, #10988, #10992, #10995) -
Dependencies: Bumped
@babel/core,@babel/preset-env,@commitlint/cli,@commitlint/config-conventional,@rollup/plugin-babel,@rollup/plugin-commonjs,@vitest/browser,@vitest/browser-playwright,eslint,lint-staged,rollup,vitest, andactions/checkout. (#10989, #10996, #10997) -
Release Metadata: Prepared the 1.18.0 release by updating package metadata and the runtime
VERSIONvalue. (#11003)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @drori12 (#10984)
- @eyupcanakman (#10899)
- @Adi-Beker (#10995)
v1.17.0
v1.17.0 — June 1, 2026
This release adds Node HTTP zstd decompression, hardens config and release workflows, and fixes authentication, header, proxy, and type-handling regressions.
🔒 Security Fixes
- Config Hardening: Guarded
socketPath,params, andparamsSerializerreads with own-property checks to prevent inherited prototype values from affecting request behavior, including SSRF-sensitive paths. (#10901, #10922) - Release Publishing: Switched the publish workflow to npm staged publishing for safer, auditable package releases with provenance. (#10926)
🚀 New Features
- HTTP Compression: Added Node HTTP adapter support for zstd response decompression, with
transitional.advertiseZstdAcceptEncodingcontrolling whetherzstdis advertised inAccept-Encoding. (#6792, #10920)
🐛 Bug Fixes
- Authentication Handling: Restored Basic auth on same-origin Node redirects while continuing to strip credentials cross-origin, and aligned the fetch adapter with HTTP adapter behavior for URL-embedded Basic auth. (#10929, #10896)
- Proxy TLS: Preserved user
httpsAgentTLS options when tunneling HTTPS requests through HTTP CONNECT proxies. (#10957) - React Native FormData: Cleared default
Content-Typefor React NativeFormDataso multipart boundaries can be generated correctly. (#10898) - Headers: Silently skipped empty or whitespace-only header names instead of throwing, matching parsed-header behavior and avoiding React Native response crashes. (#10875)
- Request Data Merging: Preserved enumerable symbol keys when cloning plain request data through axios merge logic. (#10812)
- Bundler Compatibility: Converted
resolveConfigfrom an arrow default export to a named function export to avoid webpack and Babel transform interop failures. (#10891) - Types: Corrected
AxiosHeaders.toJSON()return types and updated CommonJSisCanceltypings to narrow toCanceledError<T>. (#10956, #10952) - Build Tooling: Avoided emitting a null
Authorizationheader from the GitHub build helper whenGITHUB_TOKENis unset. (#10931)
🔧 Maintenance & Chores
- HTTP/2 Internals: Extracted
Http2Sessionsinto its own helper module and added direct unit coverage for session pooling, timeout, and cleanup behavior. (#10861) - Package Publishing: Reduced published package size by switching to a
filesallowlist and dropping unneeded unminified bundle source maps. (#10939) - CI and Release Automation: Added bundle-size reporting, moved reports to the job summary, fixed bundle-size comparison coverage, added Node 26 to the matrix, pinned npm for staged publishing, and prepared the 1.17.0 release. (#10907, #10911, #10916, #10927, #10935, #10983)
- Developer Workflow: Added a dev container and iterated on OpenSpec workflow files before removing them from the release branch. (#10925, #10914, #10958)
- Documentation and Policy: Updated disclosure, contributor, collaboration, threat-model, advanced docs, README badges, release notes, moderator configuration, and project metadata. (#10890, #10889, #10921, #10945, #10905, #10933, #10915, #10887, #10955)
- Dependencies: Bumped Babel tooling, Commitlint, ESLint, Rollup, Globals, Vitest, Playwright,
fs-extra,qs, docs dependencies, and GitHub Actions dependencies includingactions/dependency-review-actionandzizmorcore/zizmor-action. (#10871, #10879, #10918, #10919, #10934, #10947, #10954, #10960)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @BasixKOR (#6792)
- @carladams1299-lab (#10861)
- @LaplaceYoung (#10812)
- @JamieMagee (#10939)
- @RonGamzu (#10905)
- @sapirbaruch (#10891)
- @nezukoagent (#10901)
- @devareddy05 (#10929)
- @Mohammad-Faiz-Cloud-Engineer (#10922)
- @azandabot (#10931)
- @niksy (#10896)
v1.16.1
v1.16.1 — May 13, 2026
This release ships a defence-in-depth fix for prototype pollution in formDataToJSON, hardens proxy and CI workflows, restores Webpack 4 compatibility for the fetch adapter, and includes several small bug fixes and maintenance improvements.
🔒 Security Fixes
- Prototype Pollution Defence-in-Depth: Hardened
formDataToJSONagainst already-pollutedObject.prototypeby walking own properties only, so attacker-controlled keys inherited from a poisoned prototype cannot propagate through deserialization. (#7413) - Proxy Cleartext Leak: Fixed an issue where HTTPS request data could be transmitted in cleartext to an HTTP proxy under certain configurations. (#10858)
- CI Cache Removal: Removed all GitHub Actions caches as a defence-in-depth measure against cache poisoning vectors in the build pipeline. (#10882)
🐛 Bug Fixes
- Data URI Parsing: Updated the
fromDataURIregex to match RFC 2397 more strictly, fixing edge cases indata:URL handling. (#10829) - Unicode Headers: Preserved Unicode header values when running through request interceptors, so non-ASCII header content is no longer corrupted before dispatch. (#10850)
- XHR Upload Progress: Guarded against malformed
ProgressEventpayloads emitted by some environments during XHR upload, preventing crashes whenloaded/totalare missing or invalid. (#10868) - Webpack 4 Fetch Adapter: Fixed an "unexpected token" error caused by syntax in the fetch adapter that Webpack 4 could not parse, restoring compatibility for legacy bundler users. (#10864)
- Type Definitions: Made
parseRevivercontext.sourceoptional in the type definitions to align with the ES2023 specification. (#10837) - URL Object Support Reverted: Reverted the change that allowed passing a
URLobject asconfig.url(originally #10866) due to regressions; this support will be reintroduced in a later release once the underlying issues are addressed. (#10874)
🔧 Maintenance & Chores
- Cycle Detection Refactor: Replaced the array-based cycle tracker in
toJSONObjectwith aWeakSet, improving performance and memory behaviour on large nested structures. (#10832) - composeSignals Cleanup: Refactored
composeSignalsto use a clearer early-return structure, simplifying the cancellation/abort composition path. (#10844) - AI Readiness & Repo Docs: Added
AGENTS.mdand related contributor-guide updates for both human and AI agents, plus post-release documentation improvements. (#10835, #10841) - Docs Improvements: Clarified the GET request example, fixed the interceptor
ejectexample to reference the correct instance, and corrected the Buzzoid sponsor description in the README. (#10836, #10853, #10856) - Sponsorship Tooling: Fixed empty sponsor arrays in the sponsor processing script, added the ability to inject additional sponsors, updated the sponsorship link, and added a Twicsy advertisement entry. (#10843, #10859, #10869)
- Dependencies: Bumped
@commitlint/clifrom 20.5.0 to 20.5.2. (#10846)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @hpinmetaverse (#10836)
- @tommyhgunz14 (#7413)
- @abhu85 (#10829)
- @divyanshuraj1095 (#10853)
- @sagodi97 (#10856)
- @rkdfx (#10868)
- @Liuwei1125 (#10866)
v1.16.0
v1.16.0 — May 2, 2026
This release adds support for the QUERY HTTP method and a new ECONNREFUSED error constant, lands a substantial wave of HTTP, fetch, and XHR adapter bug fixes around redirects, aborts, headers, and timeouts, and welcomes 23 new contributors.
⚠️ Notable Changes
A handful of fixes in this release are either security-adjacent or change observable behaviour. Please review before upgrading:
- Fetch adapter now enforces
maxBodyLengthandmaxContentLength. These limits were silently ignored on the fetch adapter prior to 1.16.0 — anyone relying on them as a safety net (DoS protection, accidental large uploads) had no protection. (#10795) - Proxy requests now preserve user-supplied
Hostheaders. Previously, the proxy path could overwrite a customHost. Virtual-host-style routing through a proxy will now behave correctly. (#10822) - Basic auth credentials embedded in URLs are now URL-decoded. If you have percent-encoded credentials in a URL (e.g.
https://user:p%40ss@host), the decoded value is what now goes on the wire. (#10825) parseProtocolnow strictly requires a colon in the protocol separator. Strings that loosely parsed as protocols before may no longer match. (#10729)- Deprecated
unescape()replaced with modern UTF-8 encoding. Non-ASCII URL handling is now spec-correct; consumers depending on legacyunescape()quirks may see different output bytes. (#7378) transformRequestinput typing change was reverted. The typing change introduced in #10745 was reverted in #10810 after follow-up review — net behavior is unchanged from 1.15.2. (#10745, #10810)
🚀 New Features
- QUERY HTTP Method: Added support for the QUERY HTTP method across adapters and type definitions. (#10802)
- ECONNREFUSED Error Constant: Exposed
ECONNREFUSEDas a constant onAxiosErrorso callers can match connection-refused failures without comparing string literals (closes #6485). (#10680) - Encode Helper Export: Exported the internal
encodehelper frombuildURLso userland param serializers can reuse the same encoding logic that axios uses internally. (#6897)
🐛 Bug Fixes
- HTTP Adapter — Redirects & Headers: Cleared stale headers when a redirect targets a no-proxy host, fixed the redirect listener chain so listeners no longer stack across hops, restored the missing
requestDetailsargument onbeforeRedirect, preserved user-suppliedHostheaders when forwarding through a proxy, and properly URL-decoded basic auth credentials. (#10794, #10800, #6241, #10822, #10825) - HTTP Adapter — Streams & Timeouts: Preserved the partial response object on
AxiosErrorwhen a stream is aborted after headers arrive, honoured thetimeoutoption during the connect phase when redirects are disabled, and resolved an unsettled-promise hang when an aborted request was combined with compression andmaxRedirects: 0. (#10708, #10819, #7149) - Fetch Adapter: Enforced
maxBodyLength/maxContentLengthin the fetch adapter, set theUser-Agentheader to match the HTTP adapter, preserved the original abort reason instead of replacing it with a generic error, and deferred global access so importing the module no longer throws aTypeErrorin restricted environments. (#10795, #10772, #10806, #7260) - XHR Adapter: Unsubscribed the
cancelTokenandAbortSignallisteners on the error, timeout, and abort code paths to prevent leaked subscriptions. (#10787) - Error Handling: Attached the parsed response to
AxiosErrorwhenJSON.parsefails insidedispatchRequest, preventedsettlefrom emittingundefinederror codes, and tightened theparseProtocolregex to require a colon in the protocol separator. (#10724, #7276, #10729) - Types & Exports: Aligned the CommonJS
CancelTokentypings with the ESM build, fixed a compiler error caused byRawAxiosHeaders, and re-exportedcreatefrom the package index. (#7414, #6389, #6460) - UTF-8 Encoding: Replaced the deprecated
unescape()call with a modern UTF-8 encoding implementation. (#7378) - Misc Cleanup: Resolved a batch of small inconsistencies and gadget-level issues across the codebase. (#10833)
🔧 Maintenance & Chores
- Refactor — ES6 Modernisation: Modernised the
utilsmodule and XHR adapter to use ES6 features, and tidied the multipart boundary error message. (#10588, #7419) - Tests: Hardened the HTTP test server lifecycle to fix flaky
FormDataEPIPE failures, fixed Win32 platform support for the pipe tests, and corrected an incorrect test assumption. (#10820, #10791, #10796) - Docs: Documented
paramsSerializer.encodefor strict RFC 3986 query encoding, updated theparseReviverTypeScript definitions and configuration docs for ES2023, added timeout guidance to the README's first async example, and expanded notes around the recent type changes. (#10821, #10782, #10759, #10804) - Reverted: Reverted the
transformRequestinput typing change from #10745 after follow-up review. (#10745, #10810) - Dependencies: Bumped
actions/setup-node, thegithub-actionsgroup, andpostcss(in/docs) to their latest versions. (#10785, #10813, #10814) - Release: Updated changelog and packages, and prepared the 1.16.0 release. (#10790, #10834)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @singhankit001 (#10588)
- @cuiweixie (#7419)
- @iruizsalinas (#10787)
- @MarcosNocetti (#10680)
- @deepview-autofix (#10729)
- @atharvasingh7007 (#10745)
- @OfekDanny (#10772)
- @mnahkies (#7414)
- @tboyila (#10759)
- @Kingo64 (#6897)
- @ramram1048 (#6389)
- @FLNacif (#6460)
- @zozo123 (#10806)
- @pierluigilenoci (#10802)
- @afurm (#10708)
- @karan-lrn (#7378)
- @ebeigarts (#7149)
- @Raymondo97 (#10782)
- @mixelburg (#10821)
- @ashishkr96 (#10822)
- @cyphercodes (#10819)
- @Jye10032 (#7260)
- @VeerShah41 (#7276)
v1.15.2
This release delivers prototype-pollution hardening for the Node HTTP adapter, adds an opt-in allowedSocketPaths allowlist to mitigate SSRF via Unix domain sockets, fixes a keep-alive socket memory leak, and ships supply-chain hardening across CI and security docs.
🔒 Security Fixes
- Prototype Pollution Hardening (HTTP Adapter): Hardened the Node HTTP adapter and
resolveConfig/mergeConfig/validator paths to read only own properties and use null-prototype config objects, preventing pollutedauth,baseURL,socketPath,beforeRedirect, andinsecureHTTPParserfrom influencing requests. (#10779) - SSRF via
socketPath: Rejects non-stringsocketPathvalues and adds an opt-inallowedSocketPathsconfig option to restrict permitted Unix domain socket paths, returningAxiosErrorERR_BAD_OPTION_VALUEon mismatch. (#10777) - Supply-chain Hardening: Added
.npmrcwithignore-scripts=true, lockfile lint CI, non-blocking reproducible build diff, scoped CODEOWNERS, expandedSECURITY.md/THREATMODEL.mdwith provenance verification (npm audit signatures), 60-day resolution policy, and maintainer incident-response runbook. (#10776)
🚀 New Features
allowedSocketPathsConfig Option: New request config option (and TypeScript types) to allowlist Unix domain socket paths used by the Node http adapter; backwards compatible when unset. (#10777)
🐛 Bug Fixes
- Keep-alive Socket Memory Leak: Installs a single per-socket
errorlistener tracking the active request viakAxiosSocketListener/kAxiosCurrentReq, eliminating per-request listener accumulation,MaxListenersExceededWarning, and linear heap growth under concurrent or long-running keep-alive workloads (fixes #10780). (#10788)
🔧 Maintenance & Chores
- Changelog: Updated
CHANGELOG.mdwith v1.15.1 release notes. (#10781)
v1.15.1
This release ships a coordinated set of security hardening fixes across headers, body/redirect limits, multipart handling, and XSRF/prototype-pollution vectors, alongside a broad sweep of bug fixes, test migrations, and threat-model documentation updates.
🔒 Security Fixes
- Header Injection Hardening: Tightened validation and sanitisation across request header construction to close the header-injection attack surface. (#10749)
- CRLF Stripping in Multipart Headers: Correctly strips CR/LF from multipart header values to prevent injection via field names and filenames. (#10758)
- Prototype Pollution / Auth Bypass: Replaced unsafe
inchecks withhasOwnPropertyto prevent authentication bypass via prototype pollution on config objects, with additional regression tests. (#10761, #10760) withXSRFTokenTruthy Bypass: Short-circuits on any truthy non-boolean value, so an ambiguous config no longer silently leaks the XSRF token cross-origin. (#10762)maxBodyLengthWith Zero Redirects: EnforcesmaxBodyLengtheven whenmaxRedirectsis set to0, closing a bypass path for oversized request bodies. (#10753)- Streamed Response
maxContentLengthBypass: AppliesmaxContentLengthto streamed responses that previously bypassed the cap. (#10754) - Follow-up CVE Completion: Completes an earlier incomplete CVE fix to fully close the regression window. (#10755)
🚀 New Features
- AI-Based Docs Translations: Initial scaffold for AI-assisted translations of the documentation site. (#10705)
LocationRequest Header Type: AddsLocationtoCommonRequestHeadersListfor accurate typing of redirect-aware requests. (#7528)
🐛 Bug Fixes
- FormData Handling: Removes
Content-Typewhen no boundary is present onFormDatafetch requests, supports multi-select fields, cancelsrequest.bodyinstead of the source stream on fetch abort, and fixes a recursion bug in form-data serialisation. (#7314, #10676, #10702, #10726) - HTTP Adapter: Handles socket-only request errors without leaking keep-alive listeners. (#10576)
- Progress Events: Clamps
loadedtototalfor computable upload/download progress events. (#7458) - Types: Aligns
runWhentype with the runtime behaviour inInterceptorManagerand makes response header keys case-insensitive. (#7529, #10677) buildFullPath: Uses strict equality in the base/relative URL check. (#7252)AxiosURLSearchParamsRegex: Improves the regex used for param serialisation to avoid edge-case mismatches. (#10736)- Resilient Value Parsing: Parses out header/config values instead of throwing on malformed input. (#10687)
- Docs Artefact Cleanup: Removes the docs content that was incorrectly committed. (#10727)
🔧 Maintenance & Chores
- Threat Model & Security Docs: Ongoing refinement of
THREATMODEL.md, including Hopper security update, TLS and tag-replay wording, mitigation descriptions, decompression-bomb guidance, and further cleanup. (#10672, #10715, #10718, #10722, #10763, #10765) - Test Coverage & Migration: Expanded
shouldBypassProxycoverage for wildcard/IPv6/edge cases, documented and testedAxiosError.status, and migratedprogressEventReducertests to Vitest. (#10723, #10725, #10741) - Type Refactor: Uses TypeScript utility types to deduplicate literal unions. (#7520)
- Repo & CI: Adds
CODEOWNERS, switches v1.x releases to an ephemeral release branch, and removes orphaned Bower support. (#10739, #10738, #10746) - Changelog Backfill: Added missing version entries to the changelog. (#10704)
- Dependencies: Bumped
follow-redirects(1.15.11→1.16.0) in root and docs,axios(1.14.0→1.15.0) in docs, and a group of 5 development dependencies. (#10717, #10716, #10684, #10709)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @curiouscoder-cmd (#7252)
- @tryonelove (#7520)
- @darwin808 (#7314)
- @zoontek (#10702)
- @AKIB473 (#10725)