VYPR
Medium severity4.8NVD Advisory· Published Apr 10, 2026· Updated May 20, 2026

CVE-2026-40175

CVE-2026-40175

Description

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
axiosnpm
>= 1.0.0, < 1.15.01.15.0
axiosnpm
< 0.31.00.31.0

Affected products

50

Patches

Vulnerability mechanics

References

11

News mentions

2