Vulnerability library
Security checkJune 12, 2026

axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmaxios

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

axios 1.15.2 exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process (e.g. lodash _.merge / CVE-2018-16487), axios silently picks up the polluted values:

  1. Header injection - lib/utils.js line 406 builds merge()’s accumulator as result = {}, so result[targetKey] (line 414) walks Object.prototype and the polluted bucket’s own keys are copied into the merged headers and ride out on the wire. 2.

Recommendation

Update the axios package to the latest compatible version. Followings are version details:

  • Affected version(s): **<= 0.31.1 >= 1.0.0, < 1.16.0**
  • Patched version(s): **0.32.0 1.16.0**

References

Could your website be exposed too?

SmartScanner can check your website for axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 12, 2026