Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-42264

40
FAUCET Score

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

First published: May 8, 2026Last modified: May 9, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.15.2CPE matchmatch criteria
cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 32nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: axiosFixed in: 1.15.2

Vendor Advisories (1)

npmGHSA-q8qp-cvcw-x6jjhigh

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

May 5, 2026

References

access.redhat.com / errata/RHSA-2026:20889
access.redhat.com / errata/RHSA-2026:20938
access.redhat.com / errata/RHSA-2026:33173
access.redhat.com / errata/RHSA-2026:36207
access.redhat.com / errata/RHSA-2026:37287
access.redhat.com / errata/RHSA-2026:37288
access.redhat.com / errata/RHSA-2026:37297
access.redhat.com / errata/RHSA-2026:41928
access.redhat.com / errata/RHSA-2026:41951
access.redhat.com / errata/RHSA-2026:42142
access.redhat.com / security/cve/CVE-2026-42264
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-42264.json
github.com / axios/axios/commit/47915144662f2733e6c051bdcb895a8c8f0586aa
Patch
github.com / axios/axios/pull/10779
Issue TrackingPatch
github.com / axios/axios/releases/tag/v1.15.2
ProductRelease Notes
github.com / axios/axios/security/advisories/GHSA-q8qp-cvcw-x6jj
ExploitMitigationVendor Advisory