chore(deps): update dependency axios to v1.16.0 [security]#84
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update dependency axios to v1.16.0 [security]#84renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
1dfd56b to
3f1aa81
Compare
3f1aa81 to
cc1dd1b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.15.1→1.16.0Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in
parseReviverCVE-2026-42044 / GHSA-3w6x-2g7m-8v23
More information
Details
Vulnerability Disclosure: Invisible JSON Response Tampering via Prototype Pollution Gadget in
parseReviverSummary
The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any
Object.prototypepollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses — including privilege escalation, balance manipulation, and authorization bypass.The default
transformResponsefunction atlib/defaults/index.js:124callsJSON.parse(data, this.parseReviver), wherethisis the merged config object. BecauseparseReviveris not present in Axios defaults, not validated byassertOptions, and not subject to any constraints, a pollutedObject.prototype.parseReviverfunction is called for every key-value pair in every JSON response, allowing the attacker to selectively modify individual values while leaving the rest of the response intact.This is strictly more powerful than the
transformResponsegadget because:Severity: Critical (CVSS 9.1)
Affected Versions: All versions (v0.x - v1.x including v1.15.0)
Vulnerable Component:
lib/defaults/index.js:124(JSON.parse with prototype-inherited reviver)CWE
CVSS 3.1
Score: 9.1 (Critical)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NapiKey: "sk-secret-internal-key"is capturedisAdmin: false → true,role: "viewer" → "admin",balance: 100 → 999999. The response looks completely normal except for the surgically altered valuesComparison with All Known Axios PP Gadgets
Object.prototype['header']Object.prototype.transformResponseObject.prototype.proxyObject.prototype.parseRevivertruetruetrue(obvious)this.auth+ raw responseassertOptionsvalidatesUsage of "Helper" Vulnerabilities
This vulnerability requires Zero Direct User Input.
If an attacker can pollute
Object.prototypevia any other library in the stack (e.g.,qs,minimist,lodash,body-parser), the pollutedparseReviverfunction is automatically used by every Axios request that receives a JSON response. The developer's code is completely safe — no configuration errors needed.Root Cause Analysis
The Attack Path
Why
parseReviverBypasses ALL Existing ProtectionsNot in defaults (
lib/defaults/index.js):parseReviveris not defined in the defaults object, somergeConfig'sObject.keys({...defaults, ...userConfig})iteration never encounters it. The merged config has no ownparseReviverproperty.Not in assertOptions schema (
lib/core/Axios.js:135-142): The schema only contains{baseUrl, withXsrfToken}.parseReviveris not validated.No type check: The
JSON.parseAPI accepts any function as a reviver. There is no check thatthis.parseReviveris intentionally set.Works INSIDE the default transform: Unlike
transformResponsepollution (which replaces the entire transform and is caught byassertOptions),parseReviverpollution injects into the DEFAULTtransformResponsefunction'sJSON.parsecall. The default function itself is not replaced, soassertOptionshas nothing to catch.Vulnerable Code
File:
lib/defaults/index.js, line 124Proof of Concept
Verified PoC Output
Impact Analysis
1. Authorization / Privilege Escalation
2. Financial Manipulation
3. Security Control Bypass
4. Silent Data Exfiltration
The reviver function receives the original value before modification. The attacker can silently capture all API keys, tokens, internal data, and PII from every JSON response while the application continues to function normally.
5. Universal and Invisible
Recommended Fix
Fix 1: Use
hasOwnPropertycheck before usingparseReviverFix 2: Use null-prototype config object
Fix 3: Validate
parseRevivertype and sourceRelationship to Other Reported Gadgets
This vulnerability shares the same root cause class — unsafe prototype chain traversal on the merged config object — with two other reported gadgets:
transformResponsemergeConfig.js:49(defaultToConfig2)mergeConfig.jstrueproxyhttp.js:670(direct property access)http.jsparseReviverdefaults/index.js:124(this.parseReviver)defaults/index.jsWhy These Are Distinct Vulnerabilities
Object.prototypekey.transformResponseenters viamergeConfig;proxyis read directly byhttp.js;parseReviveris read inside the defaulttransformResponsefunction'sJSON.parsecall.mergeConfig.js(axios_26) does NOT fixdefaults/index.js:124(this vulnerability). Fixinghttp.js:670(axios_30) does NOT fix this either. Each requires a separate patch.transformResponseis constrained to returntrue;proxyrequires a proxy server;parseReviverenables constraint-free selective value modification.Comprehensive Fix
While each vulnerability requires a location-specific patch, the comprehensive fix is to use null-prototype objects (
Object.create(null)) for the merged config inmergeConfig.js, which would eliminate prototype chain traversal for all config property accesses and address all three gadgets at once. The maintainer may choose to assign a single CVE covering the root cause or separate CVEs for each distinct exploitation path — we defer to the maintainer's judgment on this.Resources
Timeline
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking
CVE-2026-42264 / GHSA-q8qp-cvcw-x6jj
More information
Details
Summary
Five config properties in the HTTP adapter are read via direct property access without
hasOwnPropertyguards, making them exploitable as prototype pollution gadgets. WhenObject.prototypeis polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request.Affected Properties
config.auth(lib/adapters/http.jsline 617) Injects attacker-controlledAuthorizationheader on all requests.config.baseURL(lib/helpers/resolveConfig.jsline 18) Redirects all requests using relative URLs to an attacker-controlled server.config.socketPath(lib/adapters/http.jsline 669) Redirects requests to internal Unix sockets (e.g. Docker daemon).config.beforeRedirect(lib/adapters/http.jsline 698) Executes attacker-supplied callback during HTTP redirects.config.insecureHTTPParser(lib/adapters/http.jsline 712) Enables Node.js insecure HTTP parser on all requests.Proof of Concept
Impact
Authorizationheader, leaking request contents to any server that logs auth headers.Root Cause
mergeConfig()iteratesObject.keys({...config1, ...config2}), which only returns own properties. When neither the defaults nor the user config sets these properties, they are absent from the merged config. The HTTP adapter then reads them via direct property access (config.auth,config.socketPath, etc.), which traverses the prototype chain and picks up polluted values.The
own()helper atlib/adapters/http.jsline 336 exists and guards 8 other properties (data,lookup,family,httpVersion,http2Options,responseType,responseEncoding,transport) from this exact attack. The 5 properties listed above are not included in this protection.Suggested Fix
Apply the existing
own()helper to all affected properties:Same pattern for
socketPath,beforeRedirect,insecureHTTPParser, and ahasOwnPropertycheck forbaseURLinresolveConfig.js.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Allocation of Resources Without Limits or Throttling in Axios
CVE-2026-44488 / GHSA-777c-7fjr-54vf
More information
Details
Summary
Axios versions
1.7.0through1.15.xdid not enforce configured request and response size limits when requests were sent with thefetchadapter. Applications that selectedadapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger thanmaxContentLengthormaxBodyLengthdespite those limits being explicitly configured.This can cause resource exhaustion in server-side usage when a malicious or compromised server returns an oversized response, when an attacker can supply a large
data:URL, or when an application forwards attacker-controlled request bodies through axios while relying onmaxBodyLengthas a boundary.Impact
The impact is availability-only. Affected applications may process, buffer, or transmit data beyond the configured limit, potentially exhausting memory, CPU, or network resources.
This does not affect axios’s default unlimited behaviour by itself:
maxContentLengthandmaxBodyLengthdefault to-1. The vulnerability exists when an application has configured finite limits and expects axios to enforce them.Server-side runtimes are the primary concern. Browser impact is generally constrained by the browser process and browser fetch behavior, and should not be described as server process exhaustion.
Affected Functionality
Affected functionality includes requests using the built-in
fetchadapter with finitemaxContentLengthormaxBodyLengthvalues.Relevant configurations include:
adapter: 'fetch'adapter: ['fetch', ...]whenfetchis selectedxhrnorhttpis available and axios falls back tofetchenv.fetchUnaffected functionality includes:
httpadapter enforcementTechnical Details
In vulnerable versions,
lib/adapters/fetch.jsdestructured request config withoutmaxContentLengthormaxBodyLength. The adapter dispatchedfetch()and then materialized the response throughtext(),arrayBuffer(),blob(), or related resolvers without checking the configured response limit.The fix in
e5540dcadded:maxContentLengthandmaxBodyLengthreads inlib/adapters/fetch.jsdata:URL decoded-size checksContent-Lengthresponse pre-checksReadableStreamtests/unit/adapters/fetch.test.jsProof of Concept of Attack
Workarounds
Use the Node.js
httpadapter for server-side requests where finite size limits are security-relevant.Validate or cap attacker-controlled request bodies before passing them to axios.
Reject or strictly allowlist attacker-controlled URL schemes, especially
data:URLs, before calling axios.Original Report
Summary
When Axios is used with adapter: 'fetch', configured body/response size limits are not enforced. This allows oversized uploads/downloads (including data: URLs) despite explicit limits, which can lead to memory/resource exhaustion in server-side usage.
Details
maxBodyLength and maxContentLength are not applied in the fetch adapter flow:
By contrast, the HTTP adapter enforces both limits.
PoC
Environment:
Steps:
Expected secure behavior: both requests rejected.
Observed:
Impact
Type: DoS / resource exhaustion due to limit bypass.
Impacted: applications using Axios fetch adapter as a server-side security control boundary for untrusted request/response sizes.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVE-2026-44496 / GHSA-hfxv-24rg-xrqf
More information
Details
Summary
Axios versions before
0.32.0on the0.xline and before1.16.0on the1.xline build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios readsdocument.cookie.The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read
document.cookie.Impact
Applications are affected only when attacker-controlled data can reach the XSRF cookie name configuration or a direct/unsafe call to the internal cookie helper.
This does not expose credentials, modify requests, or affect response integrity. The impact is availability only.
Affected Functionality
Affected code paths:
lib/helpers/cookies.jsread(name)in standard browser environments.lib/helpers/resolveConfig.jsin1.x, when browser XHR/fetch adapters resolve XSRF config.lib/adapters/xhr.jsin0.x, when the XHR adapter reads the configured XSRF cookie.axios/unsafe/helpers/cookies.jsin1.x, if callers pass attacker-controlled names.Unaffected code paths:
xsrfCookieName: 'XSRF-TOKEN'when not attacker-controlled.xsrfCookieName: null.document.cookie.Technical Details
Affected versions interpolate the cookie name into a regex.
Because
nameis not escaped, regex metacharacters in the cookie name are interpreted as regex syntax. A payload such as(.+)+$can force catastrophic backtracking againstdocument.cookie.The fix avoids dynamic regex construction and parses
document.cookieby splitting on;, trimming leading whitespace, and comparing cookie names with exact string equality.Proof of Concept of Attack
Expected result: timings grow rapidly as the cookie string length increases.
Workarounds
Set
xsrfCookieName: nullif the application does not need axios to read an XSRF cookie.Do not derive
xsrfCookieNamefrom untrusted input. If a dynamic cookie name is unavoidable, validate it against a strict cookie-name allowlist before passing it to axios.Avoid calling
axios/unsafe/helpers/cookies.jsdirectly with untrusted namesOriginal Source
Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
1. Title
ReDoS via Unsanitized Cookie Name in Dynamic Regular Expression Construction
2. Affected Software and Version
lib/helpers/cookies.js3. Vulnerability Type / CWE
4. CVSS 3.1 Score
Score: 7.5 (High)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H5. Description
The
cookies.read()function inlib/helpers/cookies.jsconstructs a regular expression dynamically using thenameparameter without any sanitization or escaping of special regex characters. At line 33, the code passes the rawnamevalue directly intonew RegExp():An attacker who can control or influence the cookie name parameter (e.g., via XSRF cookie name configuration, prototype pollution of
xsrfCookieName, or any code path where user input reachescookies.read()) can inject a malicious regex pattern that causes catastrophic backtracking, leading to a Denial of Service condition.With a crafted input of approximately 20-30 characters, the regex engine can be forced to consume several seconds to minutes of CPU time, effectively freezing the JavaScript event loop.
6. Root Cause Analysis
File:
lib/helpers/cookies.jsLine: 33
The vulnerability exists because:
nameparameter is concatenated directly into a regex pattern without escaping special regex metacharacters.(?:^|; )prefix combined with an injected pattern like((((.*)*)*)*)*creates nested quantifiers that cause catastrophic backtracking when the regex engine attempts to match againstdocument.cookie.The
cookies.read()function is called fromlib/helpers/resolveConfig.jsat line 61:The
xsrfCookieNamevalue comes from the Axios configuration, which can be influenced by prototype pollution or direct configuration injection.7. Proof of Concept
8. PoC Output
The exponential growth pattern is clearly visible: each additional 2 characters approximately quadruples the execution time.
9. Impact
10. Remediation / Suggested Fix
Escape all regex metacharacters in the
nameparameter before constructing the regular expression.Alternatively, avoid dynamic regex construction entirely and use string-based parsing:
11. References
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter
CVE-2026-44487 / GHSA-p92q-9vqr-4j8v
More information
Details
Summary
Axios’s Node.js HTTP adapter may forward a
Proxy-Authorizationheader to a redirected origin during specific proxy-to-direct redirect flows.This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy.
Impact
A malicious or attacker-controlled origin can cause an axios client to disclose its configured proxy credentials if all required conditions are present.
The leak is limited to Node.js HTTP adapter requests. Browser, XHR, fetch, and React Native adapter paths are not affected by this Node-specific proxy handling path.
The practical impact depends on the leaked credentials. If the credential is reusable and the proxy is reachable by the attacker, the attacker may be able to authenticate to that proxy, subject to the proxy’s own network exposure, authorisation policy, and credential scope.
Affected Functionality
Affected functionality requires all of the following:
http://request using an authenticated proxy fromconfig.proxyor proxy environment variables.HTTPS_PROXYor a matchingNO_PROXY.Unaffected functionality includes browser adapters, requests with
maxRedirects: 0, requests without proxy credentials, and redirect flows where the redirect layer stripsProxy-Authorizationbefore axios reconfigures the redirected request.Technical Details
In affected versions,
lib/adapters/http.jsaddsProxy-AuthorizationinsetProxy()when a proxy with credentials is used.Axios also installs redirect proxy handling so redirected requests can re-run proxy resolution. Before the fix, when the redirected request no longer resolved to a proxy,
setProxy()did not clear aProxy-Authorizationheader inherited from the previous request options. Iffollow-redirectsdid not remove that header for the specific redirect shape, the redirected direct request carried the stale proxy credential to the origin.The
1.xfix in commitafca61achangessetProxy(options, configProxy, location, isRedirect)so redirect re-invocation removes every case variant ofProxy-Authorizationbefore applying proxy settings for the next hop. Regression tests intests/unit/adapters/http.test.jscover no-proxy redirects,NO_PROXY, different proxy targets, casing variants, and an end-to-end redirect flow.The
0.xfixed release0.32.0includes a backport-styleremoveProxyAuthorization()guard inlib/adapters/http.js.Proof of Concept of Attack
Safe local outline using dummy credentials:
Expected vulnerable behaviour:
Expected fixed behaviour:
Workarounds
Set
maxRedirects: 0and handle redirects manually, ensuringProxy-Authorizationis not copied to requests that are not sent through the proxy.Avoid using reusable authenticated HTTP proxy credentials for requests to untrusted origins. If exposure is suspected, rotate the proxy credential.
Original Source
Summary
Axios’s Node.js
httpadapter can incorrectly forward a retainedProxy-Authorizationheader to the final HTTPS origin during certain HTTP-to-HTTPS redirect flows.When an initial HTTP request is sent through an authenticated
HTTP_PROXY, and the redirected HTTPS request is sent directly because no proxy applies to the redirected HTTPS URL, Axios retains the staleProxy-Authorizationheader and forwards it to the final origin.Details
The issue occurs during a proxy-to-direct transition across redirects.
When Axios sends an initial HTTP request through an authenticated
HTTP_PROXY, it correctly includesProxy-Authorizationfor the proxy hop. If that response redirects to an HTTPS URL on the same hostname, and no proxy applies to the redirected HTTPS URL, the redirected request is sent directly to the final origin instead of through the proxy.In the affected flow, the final HTTPS origin receives a
Proxy-Authorizationheader value that was intended only for the outbound proxy.Whether the issue is observable depends on how the redirect layer compares the host and port across the redirect. In the affected redirect shape, confidential-header handling does not remove the retained
Proxy-Authorizationheader before the redirected request is sent.Root Cause Analysis
Based on code review, Axios appears to create the stale header condition in its Node.js
httpadapter.In lib/adapters/http.js:
Proxy-Authorizationin setProxy().As a result, Axios correctly adds proxy credentials for the first proxied request, but does not clear them when a later redirected request becomes direct.
A dependent factor is the behavior of the redirect layer. In the affected redirect shape, confidential-header handling does not remove the retained
Proxy-Authorizationheader before the redirected request is sent. This appears to be why the issue is observable only for certain redirect shapes.Client Conditions
HTTP_PROXYHTTPS_PROXYis configured)Under that redirect shape, the retained
Proxy-Authorizationheader is not removed before the redirected request is sent to the final HTTPS origin.Reproduction Outline
Detailed reproduction instructions were shared with the maintainers during coordinated disclosure. The public outline below preserves the validated configuration and observable behavior needed to assess exposure, while omitting environment-specific test-harness details.
The issue was reproduced only in a researcher-controlled local test environment using dummy proxy credentials.
The issue was confirmed under the following conditions:
Observed behavior
Proxy-Authorization.Proxy-Authorizationheader.Proxy-Authorizationheader value that was intended only for the proxy.Expected behavior
Axios should not send the
Proxy-Authorizationheader on a redirected request that is no longer sent through a proxy.Impact
Under the affected redirect and proxy configuration, the final HTTPS origin may receive a retained
Proxy-Authorizationheader value that was intended only for the outbound proxy.If that credential is valid and reusable, and the outbound proxy is reachable by the attacker, the attacker may be able to authenticate to that proxy with the affected environment’s proxy credential, subject to the credential’s scope and the proxy’s access controls.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
CVE-2026-44486 / GHSA-j5f8-grm9-p9fc
More information
Details
Summary
Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a
Proxy-Authorizationheader. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the staleProxy-Authorizationheader can remain on the redirected request and be sent to the redirect target.This affects Node.js's use of Axios with automatic redirects enabled and an authenticated proxy configuration. Browser adapters are not affected.
Impact
An attacker who controls a server that the victim application requests can redirect the request so that the attacker-controlled redirect target receives the victim’s proxy credentials.
The most relevant case is a Node.js application using an authenticated
HTTP_PROXYfor an initialhttp://request, with redirects enabled, where the redirect target resolves to no proxy, such as anhttps://URL whenHTTPS_PROXYis unset.This does not affect browser, XHR, or fetch adapter behaviour. It also does not affect requests with
maxRedirects: 0.Affected Functionality
Affected functionality is limited to the Node.js HTTP adapter in
lib/adapters/http.js.Relevant inputs and settings include:
HTTP_PROXY,HTTPS_PROXY, andNO_PROXY.http://user:pass@proxy.example:8080.follow-redirects.setProxy().beforeRedirects.proxy.Technical Details
In affected v1 releases,
setProxy()addsProxy-Authorizationwhen a proxy with credentials is selected, but redirect handling callssetProxy()again without first clearing any existing proxy authorization header.If the redirected URL resolves to no proxy,
setProxy()does not add a new proxy configuration and also does not remove the old header. The redirected request can therefore carry the staleProxy-Authorizationheader to the final origin.The v1 fix in
afca61aadds anisRedirectpath that deletes any case variant ofProxy-Authorizationbefore proxy settings are re-applied on redirect. The v0 backport in2af6116fixed the 0.x line for0.32.0.Proof of Concept of Attack
Attacker-controlled HTTP endpoint:
Expected result on affected versions:
Expected result on fixed versions:
Workarounds
Set
maxRedirects: 0and handle redirects manually.Avoid using authenticated proxy environment variables for requests to untrusted HTTP origins unless redirect behaviour is controlled.
Ensure proxy environment variables are configured consistently across protocols so redirects do not unexpectedly change from proxied to direct connections.
Original Source
Summary
Axios' Node.js HTTP adapter can leak proxy credentials to a redirect target origin. When an initial request is sent through an authenticated HTTP proxy, Axios adds a
Proxy-Authorizationheader. On redirect, Axios re-evaluates proxy settings, but if the redirected request no longer uses a proxy, the staleProxy-Authorizationheader is not cleared. As a result, the redirect target can receive the proxy credential directly.This issue affects the Node.js HTTP adapter and can be reproduced when the initial request uses
HTTP_PROXYwith authentication, redirects are enabled, and the redirected request is resolved to no proxy, such as whenHTTPS_PROXYis unset or the redirect target is excluded byNO_PROXY.Details
In the current implementation:
setProxy()addsProxy-Authorizationwhen a proxy with credentials is in use.setProxy()for the redirected request.setProxy()does not clear the previously addedProxy-Authorizationheader.Relevant code locations:
lib/adapters/http.jssetProxy()addsProxy-AuthorizationbeforeRedirects.proxyPoC
GET http://<attacker-site>/startcorp proxy302 Location: https://<attacker-site>/finalProxy-AuthorizationheaderObserved output:
This demonstrates that the proxy credential is exposed to the redirect target origin.
Impact
Exposes authenticated proxy credentials to an attacker-controlled origin.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVE-2026-44495 / GHSA-3g43-6gmg-66jw
More information
Details
Summary
Axios versions before the fixed releases contain prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted
Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator.Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over
Object.prototypebefore Axios creates a request.Impact
For ordinary prototype-pollution primitives that can only assign JSON-like values, this issue primarily results in request failures or denial-of-service attacks.
If the attacker can pollute
Object.prototype.transformResponsewith a function, affected versions of Axios may execute it. In fully affected versions, the function can observe response data and request config, including URL, headers, andauth, and can change the response data returned to application code.This function-valued condition is important. Most query-string or JSON parser prototype-pollution bugs cannot create JavaScript functions on their own, so credential exposure and response tampering are conditional rather than automatic consequences of such bugs.
Affected Functionality
The affected functionality is Axios request config processing and response transformation.
Affected use requires all of the following:
Object.prototypein the same process or browser context.transformResponse.This is not specific to the Node HTTP adapter. Browser and Node usage can both pass through the shared config/transform pipeline, though real-world exploitability depends on the surrounding application and