Critical Axios Vulnerability Allows Remote Code Execution – PoC Exploit Released
ID: 6d5558f3-6ee5-5575-983b-adc144086361
STIX ID: report--6d5558f3-6ee5-5575-983b-adc144086361
Feed Name: Cyber Press
Threat Score
A critical CVE-2026-40175 vulnerability in the Axios HTTP client (header handling in lib/adapters/http.js) allows prototype-pollution-derived header injection and CRLF-based HTTP request smuggling that can bypass AWS IMDSv2, exfiltrate metadata/credentials, and lead to RCE and full cloud environment compromise; a public PoC has been published and users are urged to upgrade to patched Axios releases and audit dependencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
