CVE-2026-42264

HIGH

CVSS v3.1: 7.4 · EPSS: 0.0041 (33.1 percentile)

NetworkNo privilegesNo user interactionVendor advisory ref

Source data as of:

At a glance

Severity
HIGH
CVSS
7.4 v3.1 · NVD
EPSS
0.0041 (33.1 percentile) · FIRST.org
CISA KEV
No
Attack conditions (CVSS vector)
NetworkNo privilegesNo user interaction · Source: NVD Vector
Affected vendors
axios
Published
2026-05-08 · Modified: 2026-06-30

CVSS / EPSS / KEV

CVSS v3.1 7.4 / 10 HIGH Source: NVD
EPSS 0.0041 33.1 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

Record details

CVE ID
CVE-2026-42264
CVSS (v3.1)
7.4 (HIGH)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability subscore
2.2
Impact subscore
5.2
EPSS
0.0041 (33.1 percentile) — 2026-06-30
CISA KEV
No
Weakness (CWE)
CWE-1321, CWE-915
Affected vendors
axios
Affected configurations (CPE)
1
Published
2026-05-08
Modified
2026-06-30
Status
Modified

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.