Axios patched several high-severity vulnerabilities affecting its Node.js HTTP adapter, including CVE-2026-40175, a critical flaw in versions below 1.13.2 that Singapore's CSA said could enable unauthenticated SSRF, potential remote code execution, and full cloud compromise. Separate disclosures also detailed CVE-2026-42264, which affects Axios 1.0.0 through 1.15.1 and allows attacker-controlled values inherited from a polluted Object.prototype to alter request behavior, enabling credential injection, request redirection, SSRF to Unix sockets, arbitrary code execution during redirects, and weaker HTTP parsing. Axios fixed that issue in 1.15.2 after merging hardening changes into the main branch.
A later advisory described CVE-2026-44494, another prototype-pollution gadget in Axios's handling of config.proxy that affects versions from 1.0.0 up to but not including 1.16.0, with the 0.x branch also tracked as affected below 0.32.0. If an application already contains a separate prototype-pollution source, the flaw can silently route outbound Axios traffic through an attacker-controlled proxy, exposing Authorization headers, cookies, and request bodies while allowing forged responses and full man-in-the-middle interception. Axios addressed the issue in 1.16.0, and a backport commit for the 0.x line added null-prototype object merging and other hardening measures to reduce prototype-pollution risk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
ZeroPath published technical analysis of CVE-2026-44494, including proof-of-concept and detection guidance. The write-up described how the Axios Node.js HTTP adapter could turn existing prototype pollution elsewhere in an application's dependency tree into a full man-in-the-middle attack.
Axios addressed CVE-2026-44494 in version 1.16.0. The vulnerability let a polluted `Object.prototype.proxy` value be treated as valid proxy configuration, enabling attacker-controlled interception of outbound requests in affected Node.js applications.
GitLab's Advisory Database published an entry for CVE-2026-44494 affecting Axios. The advisory identified the issue as a full man-in-the-middle risk via a prototype pollution gadget in `config.proxy`.
ZeroPath published details for CVE-2026-42264, describing prototype pollution gadget chains in Axios versions 1.0.0 through 1.15.1 and noting impacts such as request hijacking, credential injection, SSRF to Unix sockets, and possible code execution during redirects.
Axios fixed CVE-2026-42264 in version 1.15.2 after merging PR #10779 and commit 47915144662f2733e6c051bdcb895a8c8f0586aa in April 2026. The flaw allowed multiple inherited configuration properties in the Node.js HTTP adapter to be influenced through prototype pollution gadgets.
A GitHub commit backported security and hardening changes from the v1.x branch into Axios's v0.x line around version 0.33.0. The changes included null-prototype object merging and other mitigations aimed at reducing prototype-pollution and related risks.
Axios disclosed and patched CVE-2026-40175 on 2026-04-16. The vulnerability affected Axios npm versions below 1.13.2 and was described as enabling SSRF that could lead to remote code execution and full cloud compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
zeropath.com
Open sourceadvisories.gitlab.com
Open sourcezeropath.com
Open sourcegithub.com
Open sourcecsa.gov.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.