PT-2026-2093 · Axios4Go · Axios4Go

Rezmoss

·

Publicado

2026-01-07

·

Atualizado

2026-03-09

·

CVE-2026-21697

CVSS v4.0

8.2

Alta

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions axios4go versions prior to 0.6.4
Description axios4go is a Go HTTP client library affected by a race condition in its shared HTTP client configuration. The global defaultClient is modified during request execution without proper synchronization, altering the shared http.Client's Transport, Timeout, and CheckRedirect properties. Applications using axios4go with concurrent requests (multiple goroutines, GetAsync, PostAsync, etc.), different proxy configurations, or handling sensitive data like authentication credentials and API keys are potentially impacted. The vulnerability allows for potential proxy configuration leaks.
Recommendations Versions prior to 0.6.4 should be updated to version 0.6.4 or later.

Exploit

Correção

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21697
GHSA-CMJ9-27WJ-7X47

Produtos afetados

Axios4Go