Description
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fvcv-3m26-pcqx | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain |
References
History
Fri, 10 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0. | |
| Title | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain | |
| Weaknesses | CWE-113 CWE-444 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-10T19:23:52.285Z
Reserved: 2026-04-09T20:59:17.618Z
Link: CVE-2026-40175
No data.
Status : Received
Published: 2026-04-10T20:16:22.800
Modified: 2026-04-10T20:16:22.800
Link: CVE-2026-40175
No data.
OpenCVE Enrichment
No data.
Github GHSA