Download Latest Version v1.20.0 source code.zip (1.1 MB)
Email in envelope

Get an email when there's a new version of Axios

Home / v1.20.0
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-08-19 3.2 kB
v1.20.0 source code.tar.gz 2026-08-19 898.9 kB
v1.20.0 source code.zip 2026-08-19 1.1 MB
Totals: 3 Items   2.0 MB 14

v1.20.0 — August 19, 2026

This release hardens runtime option handling, adds RFC 9110 status-code aliases, fixes Node.js and XHR reliability issues, and refreshes project tooling and documentation.

⚠️ Breaking Changes & Deprecations

  • HTTP Status Naming: Added ContentTooLarge (413) and UnprocessableContent (422), while retaining PayloadTooLarge and UnprocessableEntity as backward-compatible deprecated aliases. (#11082)

🔒 Security Fixes

  • Runtime Option Handling: Hardened behavioral configuration reads against shared and foreign prototype pollution and normalized unsafe interceptor replacement objects. This also clarifies Fetch redirect and custom implementation behavior, HTTP/2 DNS and proxy handling, CIDR-based NO_PROXY matching, and malformed data URI rejection; see the PR for documented compatibility effects. (#11141)

🐛 Bug Fixes

  • Interceptor Lifecycle: Prevented unbounded handler-array growth by trimming trailing ejected interceptors without changing iteration semantics, and kept interceptor operations safe when the public handlers field is nullish. (#11087, [#11118])
  • Request Error Preservation: Prevented custom Error.prepareStackTrace implementations that return non-string values from replacing the original request failure with an unrelated TypeError. (#11109)
  • XHR Reliability: Navigation-canceled requests now reject with ECONNABORTED instead of resolving with status 0, while successful downloads flush their final progress callback during the live loadend dispatch. (#11094, [#11121])
  • Node.js Socket Memory: Removed request-context retention from per-socket error listeners, preventing completed response data from being pinned for the lifetime of pooled keep-alive sockets. (#11091)
  • Core Methods and HTTP Errors: Prevented structural method-header buckets from leaking into outgoing headers, standardized invalid DNS lookup and httpVersion failures as AxiosError.ERR_BAD_OPTION_VALUE, and corrected the timeoutErrorMessage merge strategy. (#11096)

🔧 Maintenance & Chores

  • Dependencies: Updated fast-uri, postcss, js-yaml, mocha, development-tooling groups, and GitHub Actions dependencies. (#11092, [#11098], [#11099], [#11106], [#11107], [#11122], [#11123], [#11126], [#11127], [#11133], [#11140], [#11143], [#11144])
  • Documentation: Applied the v1.19.0 documentation updates, added the missing fs import to the README stream example, introduced localized global search, and repaired the interceptor test link. (#11101, [#11113], [#11097], [#11119])
  • Sponsorship: Updated sponsorship links and data and added ScrapingBee as a sponsor. (#11124, [#11136], [#11137])
  • CI and Release: Switched ESM smoke tests to locked dependencies and synchronized package and runtime version metadata for v1.20.0. (#11128, [#11152])

🌟 New Contributors

We are thrilled to welcome our new contributors. Thank you for helping improve axios:

  • @yens1 (#11109)
  • @Sasireddy001 (#11113)
  • @ari-token-security (#11094)
  • @timothyokooboh (#11097)
  • @gi9439041-png (#11119)
  • @Hashim1999164 (#11082)
  • @v-dev-cl (#11091)
  • @r0h1tb (#11118)
  • @ostapondo (#11121)

Full Changelog (https://github.com/axios/axios/compare/v1.19.0...v1.20.0)

Source: README.md, updated 2026-08-19