PT-2026-2093 · Axios4Go · Axios4Go
Rezmoss
·
Publicado
2026-01-07
·
Atualizado
2026-03-09
·
CVE-2026-21697
CVSS v4.0
8.2
Alta
| Vetor | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
axios4go versions prior to 0.6.4
Description
axios4go is a Go HTTP client library affected by a race condition in its shared HTTP client configuration. The global
defaultClient is modified during request execution without proper synchronization, altering the shared http.Client's Transport, Timeout, and CheckRedirect properties. Applications using axios4go with concurrent requests (multiple goroutines, GetAsync, PostAsync, etc.), different proxy configurations, or handling sensitive data like authentication credentials and API keys are potentially impacted. The vulnerability allows for potential proxy configuration leaks.Recommendations
Versions prior to 0.6.4 should be updated to version 0.6.4 or later.
Exploit
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Axios4Go