CVE-2026-44494High· 8.7▾ MidnightPoC availableAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 47.8 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.0%
Last analysed / modified upstream
Exploit / PoC code exists
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, which traverses the prototype chain. Because proxy is not present in Axios defaults, the merged config object has no own proxy property, making it trivially injectable via prototype pollution. Once injected, setProxy() routes all HTTP requests through the attacker's proxy server. This vulnerability is fixed in 1.16.0.
axios >= 1.0.0, < 1.16.0Upgrade past the affected range:
axios 1.16.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44495High· 7.0Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42044Medium· 6.5Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42041Medium· 4.8Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42033High· 7.4Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42264High· 7.4Axios is a promise based HTTP client for the browser and Node.js
CVE-2026-42043High· 7.2Axios is a promise based HTTP client for the browser and Node.js