CVE-2026-42264Disclosure(axios / axios)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch axios axios systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321CWE-915

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • axios

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-09)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
axios

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-05: 1Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Patch / Workaround · 2026-05-05: 1Technical Details · 2026-05-05: 105-0505-0805-09
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-051
Patch1
2026-05-081
Disclosure1
2026-05-092
Disclosure1General1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Axios vulnerabilities: CVE-2026-42033, CVE-2026-42035, CVE-2026-42043, CVE-2026-42264 Multiple prototype pollution issues in Axios can let attackers manipulate request configs, override headers, and potentially redirect traffic or leak sensitive data. Impacts apps using untrusted input in request building. Upgrade to the latest version ASAP and audit how user input flows into HTTP requests.

    Post summary

    The tweet alerts about prototype pollution vulnerabilities in Axios and urges immediate upgrade to the latest version.

    0101097
    121 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42264 Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, bef… https://www.cve.org/CVERecord?id=CVE-2026-42264 ----- Traducción: CVE-2026-42264 Axi… http://infoflow.cloud`

    Post summary

    The post simply announces CVE-2026-42264 affecting Axios versions up to 1.15.1, without discussing exploitation, mitigation, or technical details.

    0000029
    76 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42264 Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, bef… https://www.cve.org/CVERecord?id=CVE-2026-42264

    Post summary

    The post merely references CVE-2026-42264 in relation to Axios, without offering actionable details or context.

    00000308
    57.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-42264 📊 Severity: 7.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42264 #CVE-2026-42264 #CVE #High #CyberSecurity #InfoSec https://t.co/38i0jRz8S9

    Post summary

    The tweet announces CVE-2026-42264, noting its severity score and affecting multiple unspecified products, but provides no further technical details, proofs of concept, or exploit information.

    0000047
    157 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaxiosaxios-node.js-

Explore more