← Vulnerability feed

Vulnerability record · CVE-2026-25639 · published 9 February 2026

CVE-2026-25639: Axios vulnerability

Axios · Axios

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.

7.5 CVSS 3.1 High EPSS 1.8% · top 22.8% CWE-754 · CWE-754CWE-1287 · CWE-1287
7.5CVSS 3.1 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
50References, 1 tagged exploit
10 Sep 2026Last modified by NVD

Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/axios/axios/commit/28c721588c7a77e7503d0a434e016f852c597b57 Patch
https://github.com/axios/axios/commit/d7ff1409c68168d3057fc3891f911b2b92616f9e Patch
https://github.com/axios/axios/pull/7369 Issue Tracking
https://github.com/axios/axios/pull/7388 Issue Tracking
https://github.com/axios/axios/releases/tag/v0.30.3 Release Notes
https://github.com/axios/axios/releases/tag/v1.13.5 ProductRelease Notes
https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433 ExploitVendor Advisory
https://access.redhat.com/errata/RHSA-2026:10184
https://access.redhat.com/errata/RHSA-2026:11414
https://access.redhat.com/errata/RHSA-2026:13542
https://access.redhat.com/errata/RHSA-2026:13548
https://access.redhat.com/errata/RHSA-2026:19712
https://access.redhat.com/errata/RHSA-2026:25041
https://access.redhat.com/errata/RHSA-2026:2694
https://access.redhat.com/errata/RHSA-2026:3087
https://access.redhat.com/errata/RHSA-2026:3105
https://access.redhat.com/errata/RHSA-2026:3106
https://access.redhat.com/errata/RHSA-2026:3107
https://access.redhat.com/errata/RHSA-2026:3109
https://access.redhat.com/errata/RHSA-2026:36882
https://access.redhat.com/errata/RHSA-2026:41064
https://access.redhat.com/errata/RHSA-2026:4942
https://access.redhat.com/errata/RHSA-2026:5142
https://access.redhat.com/errata/RHSA-2026:5168
https://access.redhat.com/errata/RHSA-2026:5174
https://access.redhat.com/errata/RHSA-2026:5633
https://access.redhat.com/errata/RHSA-2026:5636
https://access.redhat.com/errata/RHSA-2026:5665
https://access.redhat.com/errata/RHSA-2026:5807
https://access.redhat.com/errata/RHSA-2026:6170
https://access.redhat.com/errata/RHSA-2026:6174
https://access.redhat.com/errata/RHSA-2026:6192
https://access.redhat.com/errata/RHSA-2026:6277
https://access.redhat.com/errata/RHSA-2026:6308
https://access.redhat.com/errata/RHSA-2026:6309
https://access.redhat.com/errata/RHSA-2026:6428
https://access.redhat.com/errata/RHSA-2026:6497
https://access.redhat.com/errata/RHSA-2026:6567
https://access.redhat.com/errata/RHSA-2026:6568
https://access.redhat.com/errata/RHSA-2026:6802

Track CVE-2026-25639 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-42043Axios server-side request forgery (ssrf) vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axio…EPSS 0.58%9.8CVE-2024-57965Axios origin validation error vulnerabilityIn axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribu…EPSS 0.38%9.1CVE-2026-42264Axios prototype pollution vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL…EPSS 0.97%9.1CVE-2026-42044Axios mass assignment vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollutio…EPSS 0.86%8.7CVE-2026-44494Axios prototype pollution vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Polluti…EPSS 0.93%8.6CVE-2026-44492Axios server-side request forgery (ssrf) vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. Wh…EPSS 0.78%8.3CVE-2026-67320Axios information exposure vulnerabilityaxios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configurat…EPSS 0.52%8.2CVE-2026-44490Axios prototype pollution vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2026-25639), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.