Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fvcv-3m26-pcqx Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:10104 cve-icon
https://access.redhat.com/errata/RHSA-2026:10153 cve-icon
https://access.redhat.com/errata/RHSA-2026:10172 cve-icon
https://access.redhat.com/errata/RHSA-2026:10175 cve-icon
https://access.redhat.com/errata/RHSA-2026:11414 cve-icon
https://access.redhat.com/errata/RHSA-2026:13542 cve-icon
https://access.redhat.com/errata/RHSA-2026:13548 cve-icon
https://access.redhat.com/errata/RHSA-2026:13571 cve-icon
https://access.redhat.com/errata/RHSA-2026:13826 cve-icon
https://access.redhat.com/errata/RHSA-2026:14774 cve-icon
https://access.redhat.com/errata/RHSA-2026:14937 cve-icon
https://access.redhat.com/errata/RHSA-2026:15091 cve-icon
https://access.redhat.com/errata/RHSA-2026:16874 cve-icon
https://access.redhat.com/errata/RHSA-2026:17468 cve-icon
https://access.redhat.com/errata/RHSA-2026:17474 cve-icon
https://access.redhat.com/errata/RHSA-2026:17657 cve-icon
https://access.redhat.com/errata/RHSA-2026:17699 cve-icon
https://access.redhat.com/errata/RHSA-2026:19712 cve-icon
https://access.redhat.com/errata/RHSA-2026:20041 cve-icon
https://access.redhat.com/errata/RHSA-2026:20938 cve-icon
https://access.redhat.com/errata/RHSA-2026:24762 cve-icon
https://access.redhat.com/errata/RHSA-2026:25041 cve-icon
https://access.redhat.com/errata/RHSA-2026:36882 cve-icon
https://access.redhat.com/errata/RHSA-2026:53661 cve-icon
https://access.redhat.com/errata/RHSA-2026:53676 cve-icon
https://access.redhat.com/errata/RHSA-2026:53735 cve-icon
https://access.redhat.com/errata/RHSA-2026:53736 cve-icon
https://access.redhat.com/errata/RHSA-2026:53752 cve-icon
https://access.redhat.com/errata/RHSA-2026:53778 cve-icon
https://access.redhat.com/errata/RHSA-2026:53789 cve-icon
https://access.redhat.com/errata/RHSA-2026:53799 cve-icon
https://access.redhat.com/errata/RHSA-2026:53835 cve-icon
https://access.redhat.com/errata/RHSA-2026:53840 cve-icon
https://access.redhat.com/errata/RHSA-2026:8483 cve-icon
https://access.redhat.com/errata/RHSA-2026:8484 cve-icon
https://access.redhat.com/errata/RHSA-2026:8490 cve-icon
https://access.redhat.com/errata/RHSA-2026:8491 cve-icon
https://access.redhat.com/errata/RHSA-2026:8493 cve-icon
https://access.redhat.com/errata/RHSA-2026:8499 cve-icon
https://access.redhat.com/errata/RHSA-2026:8500 cve-icon
https://access.redhat.com/errata/RHSA-2026:8501 cve-icon
https://access.redhat.com/errata/RHSA-2026:9742 cve-icon
https://access.redhat.com/security/cve/CVE-2026-40175 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2457432 cve-icon
https://cert-portal.siemens.com/productcert/html/ssa-876049.html cve-icon
https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c cve-icon cve-icon
https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1 cve-icon cve-icon cve-icon
https://github.com/axios/axios/pull/10660 cve-icon cve-icon cve-icon
https://github.com/axios/axios/pull/10660#issuecomment-4224168081 cve-icon
https://github.com/axios/axios/pull/10688 cve-icon cve-icon
https://github.com/axios/axios/releases/tag/v0.31.0 cve-icon cve-icon
https://github.com/axios/axios/releases/tag/v1.15.0 cve-icon cve-icon cve-icon
https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-40175 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40175.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-40175 cve-icon
History

Wed, 12 Aug 2026 12:30:00 +0000


Wed, 20 May 2026 01:30:00 +0000

Type Values Removed Values Added
Description Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1. Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.

Tue, 12 May 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 13:30:00 +0000

Type Values Removed Values Added
References

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*

Thu, 16 Apr 2026 19:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Tue, 14 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Description Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0. Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.
References

Tue, 14 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-915
References
Metrics threat_severity

None

threat_severity

Critical


Mon, 13 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Axios
Axios axios
Vendors & Products Axios
Axios axios

Mon, 13 Apr 2026 10:30:00 +0000

Type Values Removed Values Added
References

Fri, 10 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
Description Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0.
Title Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Weaknesses CWE-113
CWE-444
CWE-918
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-12T12:04:42.277Z

Reserved: 2026-04-09T20:59:17.618Z

Link: CVE-2026-40175

cve-icon Vulnrichment

Updated: 2026-04-13T09:32:22.149Z

cve-icon NVD

Status : Modified

Published: 2026-04-10T20:16:22.800

Modified: 2026-08-12T12:19:08.747

Link: CVE-2026-40175

cve-icon Redhat

Severity : Critical

Publid Date: 2026-04-10T19:23:52Z

Links: CVE-2026-40175 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T03:00:12Z