CVE-2026-25639Disclosure(axios / axios)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch axios axios systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754CWE-1287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-31); latest day: 1
  • 15 total mentions across 11 days

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline15 mentions / 11d
01234Mentions · 2026-02-09: 1Mentions · 2026-02-10: 2Mentions · 2026-02-11: 1Mentions · 2026-02-17: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-27: 1Mentions · 2026-03-31: 4Mentions · 2026-05-05: 1Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-31: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 2Technical Details · 2026-02-11: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 3Technical Details · 2026-05-05: 102-0902-1002-1102-1702-2702-2803-2703-3105-0505-1905-21
Signal classification4 categories
Disclosure
640.0%
Patch
533.3%
General
320.0%
PoC
16.7%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-02-091
Disclosure1
2026-02-102
Disclosure1Patch1
2026-02-111
PoC1
2026-02-171
Disclosure1
2026-02-271
Patch1
2026-02-281
Patch1
2026-03-271
Disclosure1
2026-03-314
Disclosure1General2Patch1
2026-05-051
Disclosure1
2026-05-191
Patch1
2026-05-211
General1
Full discourse15 posts
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-25639 : High-Severity Axios Flaw Allows Attackers to Trigger DoS and Crash Node.js Servers. 🔥PoC :https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433 📊 373K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Axios%22 👇Query HUNTER : http://product.name="Axios" 📰Refer:https://securityonline.info/http-down-high-severity-axios-flaw-cvss-7-5-crashes-node-js-servers/ https://gbhackers.com/axios-vulnerability-allows-attackers-to-trigger-dos/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces a high-severity Axios vulnerability (CVE‑2026‑25639) with a linked PoC and technical details, but it does not report active exploitation or provide exploit code.

    18028113.0K
    25.4K followersView on X
  • Amia@amia_dev
    General

    @usetraceix This is especially annoying in the nodejs ecosystem, where most "high severity" vulns are the most niche edge cases ever. Like you aren't telling me anyone passes user input to server configs like this (CVE-2026-25639): https://t.co/KG8CJv3tW6

    Post summary

    The tweet references CVE-2026-25639 as a niche high‑severity issue in the Node.js ecosystem but provides no technical details, PoC, patch information, or evidence of active exploitation.

    10052724
    919 followersView on X
  • striga@striga_ai
    Disclosure

    We used Striga to discover a high-severity vulnerability in axios, the most downloaded HTTP client in JavaScript. Any Node.js service that forwards user-controlled JSON through axios can be crashed with a single request. CVE-2026-25639. Patched in 1.13.5. https://www.striga.ai/research/crashing-axios-with-proto

    Post summary

    Striga identified a high‑severity crash vulnerability in the axios HTTP client (CVE‑2026‑25639) that can be triggered by passing user-controlled JSON; the issue is fixed in version 1.13.5.

    03041155
    85 followersView on X
  • Robin@hardzork
    General

    @euboletini @LukeberryPi nope, CVE-2026-25639 https://www.cvedetails.com/vulnerability-list/vendor_id-19831/product_id-54129/version_id-2026580/Axios-Axios-1.12.2.html

    Post summary

    A reply that references CVE-2026-25639 and links to a CVEDetails page, but provides no additional technical, exploit, or patch information.

    2002096
    22 followersView on X
  • Dr.Mashari@GMashari
    Patch

    📌 ثغرة أمنية في مكتبة Axios تتيح للمهاجمين شن هجمات حجب الخدمة (DoS) وتعطيل خوادم Node.js 🛡️ الفئة: ثغرة 📝 الملخص: تَمّ اكتشاف ثغرة أمنية عالية الخطورة تندرج تحت المعرف CVE-2026-25639 في مكتبة Axios، وهي إحدى أكثر المكتبات استخداماً في بيئة JavaScript. تكمن الثغرة في دالة mergeConfig التي تفشل في معالجة كائنات التكوين التي تحتوي على المفتاح __proto__، مما يؤدي إلى محاولة استدعاء Object.prototype كدالة، وهو ما يسبب خطأً تقنياً (TypeError) يؤدي لانهيار خادم Node.js فوراً. يستهدف الهجوم التطبيقات التي تقبل مدخلات JSON من المستخدمين وتمررها مباشرة إلى إعدادات Axios، مما يمكّن المهاجم من إخراج الخدمة عن العمل بطلب واحد فقط. — يُنصح بتحديث المكتبة إلى الإصدار 1.13.5 فوراً لسد هذه الفجوة الأمنية. 📍 تفاصيل فنية: 🎯 الهدف: تطبيقات Node.js التي تستخدم مكتبة Axios لمعالجة طلبات HTTP. 🧠 التقنية المستخدمة: استغلال خلل في منطق دمج الإعدادات عبر إرسال مفتاح __proto__ خبيث لتوليد خطأ TypeError. 🚨 الإجراء المتخذ: أصدر مطورو المكتبة تصحيحاً أمنياً في النسخة 1.13.5 لمعالجة آلية التعامل مع خصائص الكائنات. 🛑 التوصيات الأمنية: الترقية الفورية للنسخة 1.13.5 والتحقق من صحة مدخلات المستخدم قبل تمريرها لدوال التكوين. 🗓️ تاريخ النشر: 10/02/2026 🔗 للمزيد: https://cybersecuritynews.com/axios-vulnerability/

    Post summary

    High‑severity DoS vulnerability in Axios caused by malicious __proto__ key in mergeConfig; patch 1.13.5 released—update immediately to mitigate.

    01020287
    9.2K followersView on X
  • CipherEdge@cifreXnet
    Patch

    🚨 WARNING: axios (npm) just got hit with CVE-2026-25639 — CVSS 7.5 HIGH A single JSON payload crashes your entire backend: {"__proto__": {"x": 1}} That's it. If your server parses user input → passes it to axios config → instant DoS. No auth needed. Affects v1.0.0–1.13.4 (basically everyone) 4 high-severity CVEs in the last 12 months: → SSRF + credential leakage → data: URL DoS → form-data predictable boundaries → now prototype key DoS 68M+ weekly npm downloads. This library is in EVERYTHING. Patch: upgrade to 1.13.5 h/t @feross for flagging If you're running a backend that touches user input and uses axios — stop reading and go update. Now.

    Post summary

    Axios versions 1.0.0–1.13.4 are vulnerable to a prototype poisoning DoS; updating to 1.13.5 immediately mitigates the risk.

    10010225
    468 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25639 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configur… https://www.cve.org/CVERecord?id=CVE-2026-25639

    Post summary

    A TypeError crash in axios mergeConfig is disclosed, fixed in v1.13.5.

    00011294
    56.5K followersView on X
  • U N C L E BIGBAY ✨@unclebigbay143
    General

    @just_andydev yes, the first one was Denial of Service (DoS) Vulnerability in February https://nvd.nist.gov/vuln/detail/CVE-2026-25639

    Post summary

    A tweet links to the NVD entry for CVE-2026-25639 and labels it a DoS vulnerability, but supplies no PoC, exploit details, or mitigation advice.

    0001063
    3.2K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Axios の脆弱性 CVE-2026-25639 が FIX:DoS 攻撃による Node.js サーバ・クラッシュの恐れ https://iototsecnews.jp/2026/02/10/axios-vulnerability-allows-attackers-to-trigger-dos-and-crash-node-js-servers/ Node.js で高いシェアを誇る HTTP ライブラリ Axios に、サーバを停止させる攻撃が可能になる深刻な不備が発見されました。この問題の原因は、Axios が設定情報を統合する mergeConfig という内部機能において、入力されたデータのプロパティ名が適切に検証されないという点にあります。JavaScript には、すべてのオブジェクトの基盤となる “プロトタイプ” という仕組みがありますが、攻撃者が “proto” という特殊な名前を含む JSON データを送信すると、Axios が誤って処理しようとしてシステムに致命的な矛盾が生じます。その結果として、プログラムが耐えきれずに即座にクラッシュしてしまいます。ご利用のチームは、ご注意ください。 #Axios #CVE202625639 #Vulnerability

    Post summary

    CVE-2026-25639 reveals a mergeConfig bug in Axios that lets attackers send JSON with a 'proto' key to trigger a DoS crash on Node.js servers. No PoC, exploit code, or active exploitation has been reported.

    01000179
    484 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2025-12758 CVE-2025-64945 CVE-2026-27699 CVE-2026-27601 CVE-2026-27903 CVE-2026-27904 CVE-2026-26996 CVE-2026-25639 HPESBNW05056 rev.1 - HPE Unified OSS Console Assurance Monitoring (UOCAM), Multiple Vulnerabilities https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05056en_us&docLocale=en_US

    Post summary

    The text lists several CVEs and cites an HPE vendor advisory link, implying that patch or mitigation information is available through the referenced document.

    000001.5K
    6.9K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Axios, Prototype Pollution Crash, #CVE-2026-25639 (Medium) https://dailycve.com/axios-prototype-pollution-crash-cve-2026-25639-medium/

    Post summary

    A Medium‑severity prototype pollution flaw in Axios (CVE‑2026‑25639) has been disclosed, with no information on PoC, exploitation, or patches.

    0000036
    191 followersView on X
  • shΞinix ★★★@sheinix
    Disclosure

    Axios Bajo Fuego: CVE-2026-25639 Amenaza con DoS Crítico — El Cable de Seguridad Por Patch Wiresec | La Gaceta Git via @gitgazette https://www.gitgazette.com/gazette/38cfe48c-9ed4-4b10-a99d-c130c2b2d576

    Post summary

    The post announces the discovery of CVE‑2026‑25639, highlighting its potential as a critical denial‑of‑service flaw, but offers no details on exploits, patches, or active usage.

    00000248
    23.0K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-25639 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/407 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post indicates that CVE-2026-25639 has been removed from the latest AWS Lambda base images, suggesting a patch or mitigation has been applied.

    0000040
    30 followersView on X
  • VibeShield.me@vibeshield
    Patch

    🚨 Axios CVE-2026-25639 can crash your Node.js app via DoS. If you're vibecoding with Next.js or Cursor, check your package.json now. Upgrade to Axios v1.13.5+ immediately to patch the prototype handling flaw. We scan for this exact risk in VibeShield. 🔐 #NodeJS https://t.co/bVXI2ZKAkD

    Post summary

    The tweet alerts users to CVE-2026-25639, a DoS vulnerability in Axios caused by a prototype handling flaw, and advises upgrading to v1.13.5+ to mitigate the risk.

    0000058
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    Axios Vulnerability Allows Attackers to Trigger DoS and Crash Node.js Servers https://gbhackers.com/axios-vulnerability-allows-attackers-to-trigger-dos/ "The vulnerability, tracked as CVE-2026-25639, affects all versions up to and including 1.13.4."

    Post summary

    A new CVE-2026-25639 in Axios permits attackers to trigger a denial-of-service attack on Node.js servers, affecting all Axios versions through 1.13.4, with no reported active exploitation or patch yet.

    00000182
    3.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more