cvedb.io
CVE-2026-42264
HIGH · CVSS 7.4
EPSS exploitation probability: 0%
Published 2026-05-08T04:16:20.313 · Last modified 2026-07-03T13:17:11.580

Summary

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

Affected products

axios — axios

Does this affect you?

Add your gear to cvedb and we'll alert you only when axios ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.