Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w9j2-pvgh-6h63 Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://access.redhat.com/errata/RHSA-2026:14937 cve-icon
https://access.redhat.com/errata/RHSA-2026:16476 cve-icon
https://access.redhat.com/errata/RHSA-2026:16532 cve-icon
https://access.redhat.com/errata/RHSA-2026:16534 cve-icon
https://access.redhat.com/errata/RHSA-2026:16535 cve-icon
https://access.redhat.com/errata/RHSA-2026:16542 cve-icon
https://access.redhat.com/errata/RHSA-2026:16874 cve-icon
https://access.redhat.com/errata/RHSA-2026:17468 cve-icon
https://access.redhat.com/errata/RHSA-2026:17474 cve-icon
https://access.redhat.com/errata/RHSA-2026:17657 cve-icon
https://access.redhat.com/errata/RHSA-2026:17699 cve-icon
https://access.redhat.com/errata/RHSA-2026:19109 cve-icon
https://access.redhat.com/errata/RHSA-2026:19375 cve-icon
https://access.redhat.com/errata/RHSA-2026:20889 cve-icon
https://access.redhat.com/errata/RHSA-2026:20938 cve-icon
https://access.redhat.com/errata/RHSA-2026:21017 cve-icon
https://access.redhat.com/errata/RHSA-2026:21338 cve-icon
https://access.redhat.com/errata/RHSA-2026:21772 cve-icon
https://access.redhat.com/errata/RHSA-2026:22465 cve-icon
https://access.redhat.com/errata/RHSA-2026:22619 cve-icon
https://access.redhat.com/errata/RHSA-2026:22629 cve-icon
https://access.redhat.com/errata/RHSA-2026:22840 cve-icon
https://access.redhat.com/errata/RHSA-2026:23361 cve-icon
https://access.redhat.com/errata/RHSA-2026:24536 cve-icon
https://access.redhat.com/errata/RHSA-2026:24539 cve-icon
https://access.redhat.com/errata/RHSA-2026:24853 cve-icon
https://access.redhat.com/errata/RHSA-2026:24977 cve-icon
https://access.redhat.com/errata/RHSA-2026:25041 cve-icon
https://access.redhat.com/errata/RHSA-2026:25089 cve-icon
https://access.redhat.com/errata/RHSA-2026:25271 cve-icon
https://access.redhat.com/errata/RHSA-2026:25273 cve-icon
https://access.redhat.com/errata/RHSA-2026:26214 cve-icon
https://access.redhat.com/errata/RHSA-2026:26225 cve-icon
https://access.redhat.com/errata/RHSA-2026:26232 cve-icon
https://access.redhat.com/errata/RHSA-2026:33574 cve-icon
https://access.redhat.com/errata/RHSA-2026:36882 cve-icon
https://access.redhat.com/errata/RHSA-2026:50300 cve-icon
https://access.redhat.com/security/cve/CVE-2026-42041 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2461629 cve-icon
https://github.com/axios/axios/security/advisories/GHSA-w9j2-pvgh-6h63 cve-icon cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-42041 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42041.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-42041 cve-icon
History

Wed, 06 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-915
References
Metrics threat_severity

None

threat_severity

Important


Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Axios
Axios axios
CPEs cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Vendors & Products Axios
Axios axios

Fri, 24 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Description Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.
Title Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Weaknesses CWE-1321
CWE-287
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-12T12:04:54.151Z

Reserved: 2026-04-23T16:05:01.709Z

Link: CVE-2026-42041

cve-icon Vulnrichment

Updated: 2026-08-12T12:04:54.151Z

cve-icon NVD

Status : Modified

Published: 2026-04-24T18:16:31.133

Modified: 2026-08-12T12:19:12.120

Link: CVE-2026-42041

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-24T17:55:30Z

Links: CVE-2026-42041 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T02:00:12Z

Weaknesses