10.0
CRITICAL CVSS 3.1
CVE-2026-40175
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.

INFO

Published Date :

April 10, 2026, 8:16 p.m.

Last Modified :

April 21, 2026, 7:44 p.m.

Remotely Exploit :

Yes !
Affected Products

The following products are affected by CVE-2026-40175 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Axios axios
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL [email protected]
CVSS 3.1 MEDIUM [email protected]
CVSS 3.1 MEDIUM [email protected]
Solution
Update Axios to version 1.15.0 or later to prevent prototype pollution and RCE.
  • Update the Axios library to version 1.15.0 or later.
  • Review dependencies for potential prototype pollution vulnerabilities.
Public PoC/Exploit Available at Github

CVE-2026-40175 has a 12 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-40175 is associated with the following CWEs:

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

JavaScript HTML

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : April 17, 2026, 2:46 a.m. This repo has been linked 1 different CVEs too.

Axios CRLF Injection (CVE-2026-40175) 취약점 대응 가이드 및 fetch 기반 마이그레이션 분석

Updated: 2 weeks, 2 days ago
0 stars 0 fork 0 watcher
Born at : April 14, 2026, 1:33 p.m. This repo has been linked 1 different CVEs too.

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

JavaScript

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : April 14, 2026, 5:51 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 2 weeks, 3 days ago
0 stars 0 fork 0 watcher
Born at : April 14, 2026, 12:15 a.m. This repo has been linked 1 different CVEs too.

None

TypeScript CSS JavaScript

Updated: 1 week ago
0 stars 0 fork 0 watcher
Born at : April 13, 2026, 5:28 a.m. This repo has been linked 3 different CVEs too.

CVE-2026-40175

Updated: 2 weeks, 5 days ago
0 stars 0 fork 0 watcher
Born at : April 12, 2026, 10:12 a.m. This repo has been linked 1 different CVEs too.

None

Dockerfile JavaScript

Updated: 2 weeks, 4 days ago
0 stars 1 fork 1 watcher
Born at : April 11, 2026, 2:45 p.m. This repo has been linked 1 different CVEs too.

Simple commands to create a test/fake axios npm package for policy detection

Updated: 1 week, 3 days ago
0 stars 0 fork 0 watcher
Born at : April 2, 2026, 10:38 a.m. This repo has been linked 2 different CVEs too.

axios サプライチェーン攻撃 感染チェックスクリプト

PowerShell Shell

Updated: 2 weeks, 4 days ago
0 stars 0 fork 0 watcher
Born at : April 1, 2026, 3:56 a.m. This repo has been linked 1 different CVEs too.

None

HTML JavaScript CSS Gherkin

Updated: 3 days ago
0 stars 0 fork 0 watcher
Born at : July 31, 2024, 7:04 p.m. This repo has been linked 2 different CVEs too.

Getting information from libreo wallboxes

JavaScript

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : June 16, 2024, 2:33 p.m. This repo has been linked 1 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 6 days, 4 hours ago
7667 stars 1247 fork 1247 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 749 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-40175 vulnerability anywhere in the article.

  • CybersecurityNews
Critical Axios Vulnerability Allows Remote Code Execution – PoC Released

The cybersecurity community is on high alert after the disclosure of a critical security flaw in Axios, a widely used promise-based HTTP client for Node.js and browsers. Security researcher Jason Saay ... Read more

Published Date: Apr 13, 2026 (2 weeks, 3 days ago)

The following table lists the changes that have been made to the CVE-2026-40175 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Apr. 21, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    Added CPE Configuration OR *cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* versions up to (excluding) 1.15.0
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c Types: Patch
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1 Types: Patch
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/pull/10660 Types: Issue Tracking, Patch
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/pull/10688 Types: Patch
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/releases/tag/v0.31.0 Types: Release Notes
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/releases/tag/v1.15.0 Types: Product, Release Notes
    Added Reference Type GitHub, Inc.: https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx Types: Exploit, Mitigation, Vendor Advisory
    Added Reference Type CVE: https://github.com/axios/axios/pull/10660#issuecomment-4224168081 Types: Issue Tracking, Patch
  • CVE Modified by [email protected]

    Apr. 16, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    Removed CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • CVE Modified by [email protected]

    Apr. 14, 2026

    Action Type Old Value New Value
    Changed Description Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0. Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.
    Added Reference https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
    Added Reference https://github.com/axios/axios/pull/10688
    Added Reference https://github.com/axios/axios/releases/tag/v0.31.0
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Apr. 13, 2026

    Action Type Old Value New Value
    Added Reference https://github.com/axios/axios/pull/10660#issuecomment-4224168081
  • New CVE Received by [email protected]

    Apr. 10, 2026

    Action Type Old Value New Value
    Added Description Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Added CWE CWE-113
    Added CWE CWE-918
    Added CWE CWE-444
    Added Reference https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
    Added Reference https://github.com/axios/axios/pull/10660
    Added Reference https://github.com/axios/axios/releases/tag/v1.15.0
    Added Reference https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.