PT-2026-32030 · Axios · Axios

Published

2026-04-09

·

Updated

2026-05-29

·

CVE-2026-40175

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions axios versions prior to 1.15.0 axios versions prior to 0.3.1
Description The axios library is vulnerable to a gadget attack chain where prototype pollution in any third-party dependency can be escalated. This occurs because the library does not sanitize HTTP header values for carriage return and line feed (CRLF) characters, allowing an attacker to inject separate HTTP requests. This can lead to request smuggling, server-side request forgery (SSRF), and the bypass of AWS IMDSv2 to exfiltrate cloud metadata and IAM credentials, potentially resulting in remote code execution (RCE) or full cloud compromise. The issue is particularly risky when using custom axios adapters or non-standard configurations that bypass the standard Node.js HTTP stack, as the runtime typically blocks CRLF injection.
Recommendations Update axios to version 1.15.0 or newer. Update axios to version 0.3.1 or newer. As a temporary workaround, restrict the use of custom axios adapters or manual request constructions that bypass the standard HTTP stack.

Fix

LPE

RCE

HTTP Request/Response Smuggling

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-05270
CLEANSTART-2026-BE61221
CLEANSTART-2026-LC05413
CVE-2026-40175
GHSA-FVCV-3M26-PCQX

Affected Products

Axios