CVE-2026-42044Medium· 6.5▾ TwilightPoC availableAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 35.8 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
Exploit / PoC code exists
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses — including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, this.parseReviver), where this is the merged config object. Because parseReviver is not present in Axios defaults, not validated by assertOptions, and not subject to any constraints, a polluted Object.prototype.parseReviver function is called for every key-value pair in every JSON response, allowing the attacker to selectively modify individual values while leaving the rest of the response intact. This vulnerability is fixed in 1.15.2.
axios >= 1.0.0, < 1.15.1Upgrade past the affected range:
axios 1.15.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42041Medium· 4.8Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42033High· 7.4Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42264High· 7.4Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44495High· 7.0Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-44494High· 8.7Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42043High· 7.2Axios is a promise based HTTP client for the browser and Node.js