CVE-2026-42264

EUVD-2026-28505
Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 50.24%
Affected Products (NVD)
VendorProductVersion
axiosaxios
1.0.0 ≤
𝑥
< 1.15.2
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Advanced Cluster Security 4.9
1779371594 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Security for Kubernetes 4.10
1779293013 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Security for Kubernetes 4.11
1783352589 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.7
1783919486 ≤
𝑥
< *
ADP
Red HatRed Hat Migration Toolkit 1.8
1783690532 ≤
𝑥
< *
ADP
Red HatRed Hat Migration Toolkit for Applications 8.1
1785169013 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.0
1782980312 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.0
1783445546 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.1
1782980278 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.1
1783445529 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.2
1782201851 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.2
1782201812 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.3
1782980360 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.3
1783445593 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
node-axios
bookworm
no-dsa
bullseye
postponed
forky
1.18.0-1
fixed
sid
1.18.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-axios
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage