| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-898c-q2cr-xwhg | axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 11 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Axios
Axios axios |
|
| Vendors & Products |
Axios
Axios axios |
Thu, 11 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values. (1) lib/utils.js line 406 builds merge()'s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket's own keys are copied into the merged headers and ride out on the wire. (2) lib/core/mergeConfig.js line 26 builds the hasOwnProperty descriptor as a plain-object literal. Object.defineProperty reads descriptor.get/descriptor.set via the prototype chain, so a polluted Object.prototype.get or Object.prototype.set makes the call throw TypeError synchronously on every axios request. This vulnerability is fixed in 0.32.0 and 1.16.0. | |
| Title | Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-11T17:23:44.278Z
Reserved: 2026-05-06T17:18:51.783Z
Link: CVE-2026-44490
Updated: 2026-06-11T17:22:43.872Z
Status : Awaiting Analysis
Published: 2026-06-11T17:16:33.027
Modified: 2026-06-11T20:56:29.653
Link: CVE-2026-44490
No data.
OpenCVE Enrichment
Updated: 2026-06-11T21:30:05Z
Github GHSA