Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
- Severity:
- Medium
Description
No description available.
Recommendation
Update the axios package to the latest compatible version. Followings are version details:
Affected version(s): **< 0.31.0 >= 1.0.0, < 1.15.0** Patched version(s): **0.31.0 1.15.0**
References
- GHSA-fvcv-3m26-pcqx
- cert-portal.siemens.com
- CVE-2026-40175
- CWE-113
- CWE-444
- CWE-918
- CAPEC-310
- OWASP 2021-A10
- OWASP 2021-A3
- OWASP 2021-A4
- OWASP 2021-A6
Related Issues
- Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix - CVE-2026-44489
- axios has DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions - CVE-2026-44490
- Axios: Header Injection via Prototype Pollution - CVE-2026-42035
- SillyTavern has Authentication Bypass via SSO Header Injection - CVE-2026-44649
You might also like:
- Tags:
- npm
- axios
Anything's wrong? Let us know Last updated on May 20, 2026


