---
id: CVE-2026-42033
title: Axios is a promise based HTTP client for the browser and Node.js
summary: >-
  Axios is a promise based HTTP client for the browser and Node.js. Prior to
  1.15.1 and 0.31.1, when Object.prototype has been polluted by any
  co-dependency with keys that axios reads without a hasOwnProperty guard, an
  attacker can (a) sil…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-1321
  - CWE-915
vendor: axios
product: axios
affected:
  - axios < 0.31.1
  - 'axios >= 1.0.0, < 1.15.1'
patched:
  - axios 1.15.1
published: '2026-04-24'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:03.087'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42033'
references:
  - url: 'https://github.com/axios/axios/security/advisories/GHSA-pf86-5x62-jrwf'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:14937'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16476'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16532'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16534'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16535'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16542'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:16874'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17468'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17474'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17657'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17699'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19109'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:20889'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:20938'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21017'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21338'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21772'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22619'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22629'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22840'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:23361'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24536'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24539'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25041'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25089'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25271'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25273'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26214'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26225'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26232'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:33574'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36882'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:48670'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-42033'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2461607'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://github.com/axios/axios/security/advisories/GHSA-pf86-5x62-jrwf'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42033.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26234'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-42033'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42033'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-04-24T00:00:00+00:00'
epss: 0.00924
epssPercentile: 0.58776
ingestedAt: '2026-07-01T15:50:58.784Z'
---

## Overview

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.

## Affected

- `axios < 0.31.1`
- `axios >= 1.0.0, < 1.15.1`

## Remediation

Upgrade past the affected range:

- `axios 1.15.1`

## Vendor advisories

- **RHSA-2026:25089** · Red Hat · fixed in: HawtIO HawtIO 4.4.0 · released 2026-06-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:25089)
- **RHSA-2026:16874** · Red Hat · fixed in: Network Observability (NETOBSERV) 1.11.0 · released 2026-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:16874)
- **RHSA-2026:36882** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.14 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36882)
- **RHSA-2026:24539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24539)
- **RHSA-2026:25273** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-06-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:25273)
- **RHSA-2026:20938** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.9 · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20938)
- **RHSA-2026:20889** · Red Hat · fixed in: Red Hat Advanced Cluster Security for Kubernetes 4.10 · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20889)
- **RHSA-2026:22619** · Red Hat · fixed in: Red Hat Data Grid 8.6.1 · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22619)
- **RHSA-2026:21338** · Red Hat · fixed in: Red Hat Developer Hub 1.8 · released 2026-05-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:21338)
- **RHSA-2026:33574** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33574)
- **RHSA-2026:14937** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-05-07 · [advisory](https://access.redhat.com/errata/RHSA-2026:14937)
- **Red Hat VEX** · Important · affected: Migration Toolkit for Applications 8, OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 2, Red Hat build of Apicurio Registry 3, … · no fix planned: Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 2, Red Hat Build of Podman Desktop - Tech Preview, Red Hat Enterprise Linux 8, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42033.json)
