v1.20.0
Added 1
- Add RFC 9110 status-code aliases ContentTooLarge (413) and UnprocessableContent (422)
Fixed 9
- Prevent unbounded handler-array growth by trimming trailing ejected interceptors
- Keep interceptor operations safe when the public handlers field is nullish
- Prevent custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError
- Make navigation-canceled XHR requests reject with ECONNABORTED instead of resolving with status 0
- Flush successful XHR downloads' final progress callback during the live loadend dispatch
- Remove request-context retention from per-socket error listeners to prevent completed response data from being pinned for the lifetime of pooled keep-alive sockets
- Prevent structural method-header buckets from leaking into outgoing headers
- Standardize invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE
- Correct the timeoutErrorMessage merge strategy
Deprecated 1
- Deprecate PayloadTooLarge and UnprocessableEntity status-code aliases in favor of ContentTooLarge and UnprocessableContent
Security 2
- Harden behavioral configuration reads against shared and foreign prototype pollution and normalize unsafe interceptor replacement objects
- Clarify Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection
From Axios
v1.20.0 — August 19, 2026
This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.
⚠️ Breaking Changes & Deprecations
- HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)
🔒 Security Fixes
- Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)
🐛 Bug Fixes
- Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, #11118)
- Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
- XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, #11121)
- Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
- Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)
🔧 Maintenance & Chores
- Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, #11098, #11099, #11106, #11107, #11122, #11123, #11126, #11127, #11133, #11140, #11143, #11144)
- Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, #11113, #11097, #11119)
- Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, #11136, #11137)
- CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, #11152)
🌟 New Contributors
We are thrilled to welcome our new contributors. Thank you for helping improve axios:
- @yens1 (#11109)
- @Sasireddy001 (#11113)
- @ari-token-security (#11094)
- @timothyokooboh (#11097)
- @gi9439041-png (#11119)
- @Hashim1999164 (#11082)
- @v-dev-cl (#11091)
- @r0h1tb (#11118)
- @ostapondo (#11121)
Full Changelog (https://github.com/axios/axios/compare/v1.19.0...v1.20.0)