Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- Severity:
- Low
Description
No description available.
Recommendation
Update the axios package to the latest compatible version. Followings are version details:
- Affected version(s): = 1.15.2
- Patched version(s): 1.16.0
References
Related Issues
- axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions - CVE-2026-44490
- Axios: Header Injection via Prototype Pollution - CVE-2026-42035
- Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking - CVE-2026-42264
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
You might also like:
- Tags:
- npm
- axios
Anything's wrong? Let us know Last updated on June 12, 2026


