logo

CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly

ID: 1d6fe8eb-4c7e-5591-bf84-71e523bf4d90

STIX ID: report--1d6fe8eb-4c7e-5591-bf84-71e523bf4d90

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-04-12

Date Updated: 2026-04-23

Author: Ddos

...
...

**Axios CVE-2026-40175 — critical prototype pollution → RCE / cloud takeover:** A public disclosure and PoC show that prototype pollution in third-party libraries can be picked up by Axios during header merging, converted into a request-smuggling payload (due to missing CRLF validation), and used to achieve authentication bypass, cache poisoning, metadata exfiltration that defeats IMDSv2, and potential remote code execution; upgrade to Axios 1.15.0+ or validate header values as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.