CVE-2024-57965
CVE-2024-57965 is a none-severity vulnerability in Axios with a CVSS 3.x base score of 0.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-346.
Key facts
- Severity: None (CVSS 3.x base score 0.0)
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2024-53865
- Weakness: CWE-346
- Affected product: Axios
- Published:
- Last modified:
Description
In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.
Frequently asked questions
- What is CVE-2024-57965?
- In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.
- How severe is CVE-2024-57965?
- CVE-2024-57965 has a CVSS 3.x base score of 0.0, rated none severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability none.
- Is CVE-2024-57965 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2024-57965?
- CVE-2024-57965 affects Axios. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2024-57965?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2024-57965 have an EU (EUVD) identifier?
- Yes. CVE-2024-57965 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-53865.
- When was CVE-2024-57965 published?
- CVE-2024-57965 was published on 2025-01-29 and last updated on 2026-06-17.
References
- https://github.com/axios/axios/commit/0a8d6e19da5b9899a2abafaaa06a75ee548597db
- https://github.com/axios/axios/issues/6351
- https://github.com/axios/axios/pull/6714
- https://github.com/axios/axios/releases/tag/v1.7.8
Affected products (1)
- cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
More vulnerabilities in Axios
- CVE-2025-62718 — Critical (CVSS 9.9): Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly…
- CVE-2026-44494 — High (CVSS 8.7): Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is…
- CVE-2026-44492 — High (CVSS 8.6): Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise…
- CVE-2026-67321 — High (CVSS 7.5): axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js…
- CVE-2026-67320 — High (CVSS 7.5): axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios…
- CVE-2026-67317 — High (CVSS 7.5): axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch…
Other CWE-346 vulnerabilities
- CVE-2026-42901 — Critical (CVSS 10.0): Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-84140 — Critical (CVSS 9.8): Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2,…
- CVE-2026-84133 — Critical (CVSS 9.8): Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR…
- CVE-2026-84129 — Critical (CVSS 9.8): Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2,…
- CVE-2026-16375 — Critical (CVSS 9.8): Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR…
- CVE-2026-16358 — Critical (CVSS 9.8): Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR…
Browse all CWE-346 vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 170.106.103.20 (ipv4-addr)
- 157.66.35.106 (ipv4-addr)
- 172.234.29.193 (ipv4-addr)
- 113.44.176.9 (ipv4-addr)
- 158.180.72.217 (ipv4-addr)
- 8.142.178.14 (ipv4-addr)