CVE-2026-40175General(axios / axios)

CRITICALCVSS 4.8 · MEDIUM

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch axios axios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-113CWE-444CWE-918CWE-915

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 77 mentions across 17 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 52 signals
  • General: 24 classified signals
  • Disclosure: 17 classified signals
  • Peaked 12d ago at 12 mentions (2026-04-14); latest day: 1
  • 77 total mentions across 17 days

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline77 mentions / 17d
036912Mentions · 2026-04-10: 5Mentions · 2026-04-11: 9Mentions · 2026-04-12: 9Mentions · 2026-04-13: 10Mentions · 2026-04-14: 12Mentions · 2026-04-15: 8Mentions · 2026-04-16: 7Mentions · 2026-04-17: 2Mentions · 2026-04-18: 2Mentions · 2026-04-20: 3Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-24: 4Mentions · 2026-05-08: 1Mentions · 2026-05-14: 1Mentions · 2026-07-15: 1Mentions · 2026-07-21: 1PoC Mentioned / Linked · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-12: 2PoC Mentioned / Linked · 2026-04-13: 3PoC Mentioned / Linked · 2026-04-14: 2PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-20: 1Exploit Tool / Code · 2026-04-12: 2Exploit Tool / Code · 2026-04-13: 2Exploit Tool / Code · 2026-04-14: 2Exploit Tool / Code · 2026-04-15: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-12: 3Patch / Workaround · 2026-04-13: 5Patch / Workaround · 2026-04-14: 3Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-24: 3Patch / Workaround · 2026-07-21: 1Technical Details · 2026-04-10: 5Technical Details · 2026-04-11: 9Technical Details · 2026-04-12: 6Technical Details · 2026-04-13: 8Technical Details · 2026-04-14: 8Technical Details · 2026-04-15: 4Technical Details · 2026-04-16: 5Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-24: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-14: 1Technical Details · 2026-07-15: 104-1004-1104-1204-1304-1404-1504-1604-1704-1804-2004-2204-2304-2405-0805-1407-1507-21
Signal classification7 categories
General
2431.2%
Disclosure
1722.1%
Patch
1316.9%
False Positive
1316.9%
PoC
67.8%
Exploit
22.6%
Referenced assets48 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-105
Disclosure3General1Patch1
2026-04-119
Disclosure5General4
2026-04-129
Disclosure1Exploit2General4Patch2
2026-04-1310
Disclosure2False Positive2General1Patch3PoC2
2026-04-1412
Disclosure1False Positive5General2Patch2PoC2
2026-04-158
False Positive4General2Patch1PoC1
2026-04-167
Disclosure1False Positive1General5
2026-04-172
Active Exploitation1Patch1
2026-04-182
General2
2026-04-203
False Positive1General1PoC1
2026-04-221
General1
2026-04-231
General1
2026-04-244
Disclosure1Patch3
2026-05-081
Disclosure1
2026-05-141
Active Exploitation1
2026-07-151
Disclosure1
2026-07-211
Disclosure1
Full discourse20 posts
  • 嶋田大貴@shimarin
    General

    いま出てるAxiosのヤバ扱い脆弱性(CVE-2026-40175: こないだのサプライチェーン攻撃とは別)、調べてみたらprototype経由で持ってきた値を未検証でHTTPリクエストヘッダに入れてしまうって話らしくて、常にprototypeが汚染されてる前提で動かないと生き延びられないJS世界が世紀末過ぎる気がします。

    Post summary

    The post discusses Axios CVE-2026-40175, noting a prototype‑based unsanitized header injection, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    416514595265107.3K
    4.3K followersView on X
  • Hunt.io@Huntio
    PoC

    🚩New Axios Vulnerability Exposes Apps to Remote Code Execution https://cyberpress.org/axios-vulnerability-3/ Unfortunately, Axios is in the news again. A critical flaw (CVE-2026-40175) enables remote code execution and full cloud compromise. Attackers can chain prototype pollution, SSRF, and request smuggling to bypass AWS IMDSv2 and steal credentials. A public PoC is already available, increasing risk. Just two weeks after the Axios npm compromise, another critical issue emerges. If you rely on Axios, patching and dependency auditing should be a priority. #Infosec #ThreatHunting #CyberSecurity

    Post summary

    A newly discovered critical Axios vulnerability (CVE-2026-40175) enables remote code execution and potential full cloud compromise; a public PoC is available, highlighting the urgent need for patching.

    24221218924.3K
    6.4K followersView on X
  • Netlas.io@Netlas_io
    PoC

    CVE-2026-40175: Unrestricted Cloud Metadata Exfiltration in Axios, 10.0 rating😱 A critical security vulnerability in Axios allows prototype pollution in any third-party dependency to be escalated into RCE or Full Cloud Compromise. PoC is now available! 👉 https://nt.ls/i7rT8

    Post summary

    CVE-2026-40175 is a prototype‑pollution flaw in Axios that can lead to remote code execution or full cloud compromise; a proof‑of‑concept has been released, but no active exploitation or patch is reported.

    23831067913.1K
    7.5K followersView on X
  • Jihyeon Kim (김지현)@simnalamburt
    Disclosure

    CVE-2026-40175 https://nvd.nist.gov/vuln/detail/CVE-2026-40175 https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx 10.0/10.0 감동ㅠㅠㅠㅠ ALL versions affected ㅠㅠㅠ 취약점의 수준이 IRC 쓰던 시절에 \r\n 검사 안해서 "blabla\r\nPRIVMSG #spam :" 이런 메시지로 Cross-IRC scripting 하던 시절이랑 똑같음 axios 쓰지말자 ㅠㅠㅠㅠㅠㅠㅠ

    Post summary

    A new CVE-2026-40175 for Axios has been disclosed with a 10.0 severity rating and all versions affected, but no PoC, exploit tool, active exploitation, or patch information is provided.

    06412772714.2K
    6.1K followersView on X
  • りんたろー@re_taro_
    General

    なんかだめそう Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain · CVE-2026-40175 · GitHub Advisory Database https://github.com/advisories/GHSA-fvcv-3m26-pcqx

    Post summary

    The post references Axios vulnerability CVE-2026-40175, describing unrestricted cloud metadata exfiltration via header injection, and links to a GitHub advisory without further technical or exploit details.

    1121786324.0K
    2.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical CVSS 10 flaw in Axios (CVE-2026-40175) allows attackers to bypass AWS IMDSv2 and achieve RCE via header injection. Upgrade to v1.15.0 now! #AxiosVulnerability #CloudSecurity #InfoSec #NodeJS #CVE202640175 #CyberAttack https://securityonline.info/axios-vulnerability-cve-2026-40175-cloud-takeover-rce/ https://t.co/wu1sfR4Txw

    Post summary

    CVE‑2026‑40175 is a critical flaw in Axios that allows attackers to bypass AWS IMDSv2 and achieve remote code execution via header injection; a patch is available in version 1.15.0, with no evidence of active exploitation reported.

    021059356.2K
    12.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40175 Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Pro… https://www.cve.org/CVERecord?id=CVE-2026-40175

    Post summary

    The CVE-2026‑40175 describes a gadget-based attack chain affecting Axios before v1.15.0, but no PoC, exploit, active usage, or patch information is provided.

    0114341725.4K
    57.7K followersView on X
  • Aikido Security@AikidoSecurity
    False Positive

    There's a new "critical 10/10" CVE in Axios. CVE-2026-40175... that's not really exploitable. Headlines about AWS credential theft, IMDSv2 bypass, full cloud compromise. We confirmed with Raul Vega Del Valle, the researcher who found it: in standard Node.js environments, this is not realistically exploitable. The attack chain depends on CRLF header injection. Node has blocked that at the runtime level for years. The chain breaks before it starts.

    Post summary

    The post conveys that CVE-2026-40175 is unlikely to be exploitable, with confirmation from the researcher who discovered it.

    31103155.7K
    11.8K followersView on X
  • The Sincere VP@thesincerevp
    Patch

    I am a principal security engineer at a company that runs 340 microservices on AWS. Three days ago, my weekend ended. CVE-2026-40175 dropped Thursday. CVSS 10.0. The vulnerability is in Axios — the HTTP library downloaded 98 million times a week. 3.75 billion times last year. It's in everything. Your bank's mobile app. Your hospital's patient portal. The internal dashboard your CFO checks before earnings calls. Every Node.js backend that makes an HTTP request probably touches it. Here's what makes this one different from every other dependency scare. The attack doesn't require anyone to use Axios incorrectly. Your developer can write the most secure, hardcoded, by-the-book API call imaginable — `axios.get('https://analytics.internal/pings')` — and it's still the entry point. Because the vulnerability isn't in how you call Axios. It's in how Axios processes headers it inherits from JavaScript's prototype chain. The chain works like this. An attacker pollutes Object.prototype through any other vulnerable library in your stack — could be a query parser, a config reader, anything. Axios automatically merges those polluted properties into its request headers during config resolution. And because Axios never sanitized header values for carriage return and line feed characters, the attacker can inject an entirely separate HTTP request inside your legitimate one. That second request? It goes to 169.254.169.254 — the AWS metadata service. It sends the exact headers needed to bypass IMDSv2, which was supposed to be the fix for the last generation of cloud SSRF attacks. It retrieves a session token. Then it uses that token to pull your IAM credentials. Full cloud compromise. From a library that was just sitting in your node_modules being helpful. I spent Saturday auditing our dependency tree. 340 services. 287 of them import Axios. 193 of those also import at least one library with a known prototype pollution path. We had 193 services where this attack chain was theoretically completable, and we didn't know until Thursday. The patch is one conditional. A regex check for \r\n in header values before they hit the socket. Seven lines of code. It's been missing from every version of Axios ever shipped — v0.1.0 through v1.14.x. Fourteen years of releases. Billions of installs. One regex. What keeps me up isn't the vulnerability. It's that Axios is maintained by essentially one person. Jason Saayman. One human being standing between 98 million weekly downloads and a config merge function that nobody audited for fourteen years. We have companies worth $3 trillion running production infrastructure on a mass of open-source code where the critical-path header sanitization was just... never written. The scariest part is the timeline. The advisory was published Thursday evening. It's now Sunday. Pinned dependencies. Cached lockfiles. CI pipelines that haven't run since Wednesday. Teams that won't see the Dependabot alert until Monday standup. The patch exists. The question is how many of those 98 million weekly downloads are still pulling a version that shipped without seven lines of input validation. Every AWS environment running unpatched Axios next to any prototype-pollution-susceptible library is one crafted query string away from credential exfiltration. And most of those teams don't know it yet. This is a fictional narrator. The numbers are real.

    Post summary

    CVE‑2026‑40175 is a critical SSRF vulnerability in Axios caused by unsanitized header values inherited from prototype pollution; a simple regex patch exists to fix it.

    46016122.6K
    1.8K followersView on X
  • Kyohei - OSS, 外資IT@labelmake
    General

    Axios CVE-2026-40175: 深刻度10/10なのに実質悪用不可能な話、aikidoからも記事が出てた > 標準的なNode.js環境では、この脆弱性を悪用することは現実的に不可能です。 https://www.aikido.dev/blog/axios-cve-2026-40175-a-critical-bug-thats-not-exploitable

    Post summary

    The article notes that CVE‑2026‑40175 has a 10/10 severity rating but is not realistically exploitable in a standard Node.js environment, with no mention of PoC, exploit code, or patch.

    0111164.3K
    8.5K followersView on X
  • Sam Stepanyan@securestep9
    Disclosure

    #Axios - yet another issue with this popular #NPM library: A newly discovered critical vulnerability CVE-2026-40175 in axios has exposed countless web & cloud apps to potential Remote Code Execution (#RCE) and full infrastructure compromise: 👇 https://cyberpress.org/axios-vulnerability-3/

    Post summary

    A new critical CVE-2026-40175 in axios is disclosed with potential for remote code execution, yet no PoC, exploit script, patch, or reported active exploitation is mentioned.

    041831.5K
    7.4K followersView on X
  • みーくん@挙動不審の限界サボレーナイ(仮)@mmixx15_eve
    General

    axiosがまた脆弱性(CVE-2026-40175)出てたけど わりと生ぬるいくせにCVEのスコアが最高点の10.0を叩き出してた これが10.0なら 3月31日に出たaxiosのポイズニングはスコア5億点やな 評価方法が機械的だからこうなる

    Post summary

    The author comments that the axios CVE-2026-40175 is relatively mild but received a perfect 10.0 CVSS score, criticizing the mechanical scoring method.

    100140177
    3.2K followersView on X
  • 西野@nishino_hiroki
    General

    CVE-2026-40175 これ、本当に9.9 (10.0)か?あれ?

    Post summary

    The user is questioning the reported CVSS score of CVE-2026-40175 but otherwise provides no additional technical or exploitation information.

    410601.8K
    1.1K followersView on X
  • Nicolas Krassas@Dinosn
    False Positive

    Axios 10 / 10 CVE is not realistically exploitable - CVE-2026-40175 https://www.reddit.com/r/cybersecurity/comments/1slaaih/axios_10_10_cve_is_not_realistically_exploitable/

    Post summary

    A Reddit discussion claims that CVE-2026-40175 in Axios 10/10 is not realistically exploitable, indicating that the vulnerability may be a false positive or an overestimated risk.

    010811.7K
    157.5K followersView on X
  • woto@f3o23rkf
    False Positive

    @jasonsaayman CVE-2026-40175 (CVSS 10) claims prototype pollution in any dependency escalates to RCE via axios header injection, CRLF request smuggling, and AWS IMDS access. I believe this is technically incorrect. Please see the thread and let me know if I'm wrong.

    Post summary

    The tweet questions the validity of CVE‑2026‑40175’s reported exploitation methods, suggesting the claim may be incorrect, without providing PoC, exploit code, or patch information.

    11052690
    74 followersView on X
  • すてにゃん@stefafafan
    False Positive

    “Axios CVE-2026-40175: a critical bug that’s… not exploitable” https://htn.to/yav9yMnWRh

    Post summary

    The post dismisses Axios CVE‑2026‑40175 as non‑exploitable, countering initial reports of critical impact.

    120321.1K
    1.5K followersView on X
  • Shingo Sasaki@s_sasaki_0529
    False Positive

    axios の最新脆弱性、任意コード実行の経路はあるものの、通常は Node.js の制約(おそらくブラウザでも)で再現不可能なので、騒がれるほどの問題ではないという話。 CVEは組み合わせでなく単体での可能性があれば付くから、実用面との乖離があって優先度判断ムズそうね。 https://www.aikido.dev/blog/axios-cve-2026-40175-a-critical-bug-thats-not-exploitable

    Post summary

    The article notes that CVE‑2026‑40175 offers a path to arbitrary code execution but practical constraints in Node.js (and likely browsers) prevent realistic exploitation, with no active attacks or patches reported.

    11030284
    539 followersView on X
  • まー@tomo_masakura
    False Positive

    CVE-2026-40175 の追加調査を更新しました。いろいろ情報をくださった方、ありがとうございます。 * いにしえの Node.js を使えば出るかも * プロトタイプ汚染があっても問題はない スコア 10 は厳しすぎるってレベルじゃなくて、そもそも脆弱性とすべきではないのかも。 https://zenn.dev/masakura/articles/bc88704f8af091

    Post summary

    The post updates on CVE-2026-40175, noting prototype pollution but questioning its severity and suggesting it may not be a genuine vulnerability, with no PoC or patch details provided.

    00140312
    309 followersView on X
  • 波乗野郎@shojiueda
    False Positive

    axios の CVE-2026-40175 を調べました 結論:Node.js + axios 環境では、この脆弱性はほぼ成立しないというのが今日時点の結論 Node.js の http モジュールが古くから CRLF を含むヘッダー値を弾いているため。axios 1.15.0 の修正は、あくまで defense in depth。

    Post summary

    The post concludes that CVE‑2026‑40175 is unlikely to be exploitable in typical Node.js + axios setups because the Node.js HTTP module rejects CRLF headers, and notes that a patch (axios 1.15.0) is available.

    110301.0K
    1.7K followersView on X
  • motch | セキュリティ🛡️@motch_dev
    Disclosure

    🚨Axiosで深刻な脆弱性が発覚(CVE-2026-40175) Axios(1.15.0未満)にヘッダーインジェクションの脆弱性。他ライブラリのプロトタイプ汚染と連鎖し、AWS認証情報窃取やRCEを招く恐れがあります。 https://github.com/advisories/GHSA-fvcv-3m26-pcqx #脆弱性 #Axios https://t.co/ZHsx7k7TeU

    Post summary

    The tweet announces a header injection flaw (CVE‑2026‑40175) affecting Axios <1.15.0, notes its linkage to prototype pollution that could enable AWS credential theft or RCE, and provides a GitHub advisory link.

    100041.5K
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more