← Späť na vyhľadávanie CVE

CVE-2026-42041

Axios

Popis

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution -Gadget- attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript-s in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.

CVSS 4.8EPSS 0.611%Riziko 0.51
Zobraziť zdroj
Zverejnené
2026-04-24 18:16:31
Dotknuté verzie
<0.31.1,<1.15.1
Typ
Package
Posledná úprava
2026-08-10 13:19:24
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N