CVE-2026-40175 (CVSS 10): Critical Axios Vulnerability and Exploit Code Disclosed Publicly
ID: 1d6fe8eb-4c7e-5591-bf84-71e523bf4d90
STIX ID: report--1d6fe8eb-4c7e-5591-bf84-71e523bf4d90
Feed Name: securityonline.info
**Axios CVE-2026-40175 — critical prototype pollution → RCE / cloud takeover:** A public disclosure and PoC show that prototype pollution in third-party libraries can be picked up by Axios during header merging, converted into a request-smuggling payload (due to missing CRLF validation), and used to achieve authentication bypass, cache poisoning, metadata exfiltration that defeats IMDSv2, and potential remote code execution; upgrade to Axios 1.15.0+ or validate header values as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
