PT-2026-7150 · Axios+1 · Axios+1

Hackerman70000

·

Published

2026-02-08

·

Updated

2026-05-21

·

CVE-2026-25639

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Axios versions prior to 0.30.3 Axios versions prior to 1.13.5
Description The mergeConfig() function in Axios crashes with a TypeError when processing configuration objects that contain proto as an own property. This occurs because when proto is present (for example, when created via JSON.parse()), the function performs a prototype chain lookup that returns Object.prototype instead of a function, leading to a crash. A remote attacker can exploit this by providing a malicious configuration object, resulting in a complete denial of service. This issue affects Node.js servers and any backend that passes user-controlled JSON to Axios configuration methods.
Recommendations Update to version 0.30.3 or later. Update to version 1.13.5 or later. As a temporary workaround, avoid passing user-controlled input directly into the Axios configuration object, specifically ensuring that input parsed via JSON.parse() is validated to remove the proto property before being processed by mergeConfig().

Exploit

Fix

DoS

Prototype Pollution

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2026-01948
CLEANSTART-2026-LC05413
CVE-2026-25639
GHSA-43FC-JF86-J433
RHSA-2026:6277

Affected Products

Axios
Confluence