A high-severity flaw in the Axios HTTP client, tracked as CVE-2026-67320, can cause Node.js applications to send requests through an attacker-controlled proxy when the Node HTTP adapter is used and prototype pollution has already compromised Object.prototype. The issue stems from request configuration hardening being undone by common interceptor patterns such as object spreading or Object.assign, allowing a polluted proxy property to be inherited through the prototype chain. Affected versions are 0.31.1 through 0.32.9 and 1.15.2 through 1.17.9, with fixes released in 0.33.0 and 1.18.0.
Successful exploitation can expose plaintext HTTP traffic, including Authorization headers, Basic auth credentials from config.auth, request methods, full URLs, Host headers, and request bodies, while also enabling attackers to return manipulated responses to the application. Italian authorities reported that a proof-of-concept exploit is now publicly available, increasing the urgency for organizations using vulnerable Axios versions in Node.js environments to patch promptly. The advisory notes there is no demonstrated browser impact and no HTTPS header or body disclosure under normal TLS validation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-67320 was published as a high-severity Axios vulnerability with a CVSS 4.0 score of 8.3. The advisory described information exposure risks for plaintext HTTP traffic in affected Axios versions used in Node.js environments.
A proof-of-concept exploit was reported as available for CVE-2026-67320, demonstrating exploitability of the Axios flaw under conditions involving prior prototype pollution. The notice warned that exploitation could expose credentials, tokens, headers, URLs, request data, and enable response manipulation.
The vulnerability affecting Axios in Node.js HTTP adapter usage was fixed in Axios versions 0.33.0 and 1.18.0. The issue allowed attacker-controlled proxy routing when prototype pollution and common interceptor patterns caused proxy settings to be read through the prototype chain.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.