logo

HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers

ID: 5f15826f-dd15-56a5-8d48-eb8a83b83b42

STIX ID: report--5f15826f-dd15-56a5-8d48-eb8a83b83b42

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2026-25639, CVSS 7.5) in Axios' mergeConfig causes a TypeError when configuration objects contain __proto__, allowing an attacker to trigger a crash via a malicious JSON payload and produce a denial-of-service against Node.js processes; maintainers released fixes in Axios 1.13.4/1.13.5 and users are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.