CVE-2026-25639High· 7.5▾ TwilightAxios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own proper…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
2.6%
2.6% → 2.8%
Last analysed / modified upstream
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing proto as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.
axios < 0.30.3axios >= 1.0.0, < 1.13.5Upgrade past the affected range:
axios 1.13.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40175Medium· 4.8Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44496High· 7.5Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44488High· 7.5Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44486High· 7.5Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44495High· 7.0Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44494High· 8.7Axios is a promise based HTTP client for the browser and Node.js