HTTP Down: High-Severity Axios Flaw (CVSS 7.5) Crashes Node.js Servers
ID: 5f15826f-dd15-56a5-8d48-eb8a83b83b42
STIX ID: report--5f15826f-dd15-56a5-8d48-eb8a83b83b42
Feed Name: securityonline.info
Threat Score
A high-severity vulnerability (CVE-2026-25639, CVSS 7.5) in Axios' mergeConfig causes a TypeError when configuration objects contain __proto__, allowing an attacker to trigger a crash via a malicious JSON payload and produce a denial-of-service against Node.js processes; maintainers released fixes in Axios 1.13.4/1.13.5 and users are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
