A critical vulnerability in the Axios HTTP client library, tracked as CVE-2026-40175, allows attackers to turn polluted JavaScript object properties into malicious HTTP headers and abuse outbound requests for SSRF, request smuggling, and potential remote code execution. Researchers said the flaw stems from improper header handling in Axios’s HTTP adapter and unsafe config merging, which can let Object.prototype values containing CRLF characters be injected into requests. The issue can be chained with prototype pollution in other npm packages to target internal services, including the AWS EC2 metadata endpoint at 169.254.169.254, potentially bypassing IMDSv2 and exposing cloud credentials or broader infrastructure.
A public proof-of-concept was released alongside disclosure, raising urgency for defenders even though active exploitation had not been confirmed at the time of reporting. The flaw affects Axios versions before 1.13.2, while maintainers said 1.15.0 introduces strict header validation that blocks CRLF-based header injection; organizations were urged to upgrade and audit dependencies such as body-parser, qs, and minimist for prototype pollution paths. One report cited internet-wide estimates of more than 48,000 potentially exposed instances, underscoring the risk of unauthorized internal access and possible full cloud compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Netlas estimated that over 48,000 instances may be directly exposed to the Axios vulnerability, though reporting said active exploitation had not yet been observed and real-world severity was still being evaluated.
A public proof-of-concept exploit for the Axios flaw was released by maintainer Jason Saayman shortly after disclosure, increasing urgency for defenders to patch and assess exposure.
Axios released version 1.15.0 to address the vulnerability by enforcing stricter header validation and rejecting headers containing CRLF characters. The issue affects versions prior to 1.13.2, and reporting recommends upgrading to the fixed release.
A critical flaw in the Axios HTTP client, tracked as CVE-2026-40175, was publicly disclosed as enabling request smuggling, SSRF abuse, AWS IMDSv2 bypass, and possible remote code execution or broader cloud compromise when chained with prototype pollution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cyberpress.org
Open sourcethestack.technology
Open sourcecvereports.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.