CVE-2026-25639
EUVD-2026-685009.02.2026, 21:15
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| axios | axios | 𝑥 < 0.30.3 |
| axios | axios | 1.0.0 ≤ 𝑥 < 1.13.5 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:2.6.7-1.el9ap ≤ 𝑥 < * | ADP |
| Red Hat | multicluster engine for Kubernetes 2.10 | 1777128790 ≤ 𝑥 < * | ADP |
| Red Hat | multicluster engine for Kubernetes 2.6 | 1776223790 ≤ 𝑥 < * | ADP |
| Red Hat | multicluster engine for Kubernetes 2.7 | 1773100128 ≤ 𝑥 < * | ADP |
| Red Hat | multicluster engine for Kubernetes 2.8 | 1775116156 ≤ 𝑥 < * | ADP |
| Red Hat | multicluster engine for Kubernetes 2.9 | 1777301444 ≤ 𝑥 < * | ADP |
| Red Hat | Network Observability \(NETOBSERV\) 1.11.0 | 1774431392 ≤ 𝑥 < * | ADP |
| Red Hat | Network Observability \(NETOBSERV\) 1.11.0 | 1774431617 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | 1783350952 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.12 | 1773259174 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.13 | 1775116130 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.14 | 1783451729 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.15 | 1776927126 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.5 | 1774446874 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1774243862 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | 1774363040 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Developer Hub 1.8 | 1774545605 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Developer Hub 1.9 | 1775140647 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Discovery 2 | 1770913709 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Migration Toolkit 1.8 | 1780590717 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.16 | 1774282136 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1776742021 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 2.25 | 1776742141 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1779189627 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1778473763 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift AI 3.3 | 1778666987 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1775577192 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1773746857 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1773849532 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Dev Spaces 3.27 | 1774448966 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Dev Spaces 3.27 | 1774476526 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Dev Spaces 3.27 | 1774227265 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Pipelines 1.21 | 1774871390 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 2.6 | 1771229736 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 2.6 | 1771230055 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 3.0 | 1771372940 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 3.0 | 1771373071 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 3.1 | 1771372942 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 3.1 | 1771385160 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 3.2 | 1771229583 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat OpenShift Service Mesh 3.2 | 1771385315 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.1 | 1773971077 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.12 | 1773771962 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.15 | 1775169219 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.16 | 1775069491 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.16 | 1775169226 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Quay 3.9 | 1773936323 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.18 | 1776250950 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.18 | 1776216284 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Satellite 6.18 | 1776269713 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Trusted Artifact Signer 1.3 | 1771324807 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-754 - Improper Check for Unusual or Exceptional ConditionsThe software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.
- CWE-1287 - Improper Validation of Specified Type of InputThe product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
Vulnerability Media Exposure
References