Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-40175 Details

Description

Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2026:10104 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:10153 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:10172 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:10175 redhat-SADP
https://access.redhat.com/errata/RHSA-2026:11414 redhat-SADP

see all 54 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')[email protected]
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')[email protected]
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributesredhat-SADP
CWE-918Server-Side Request Forgery (SSRF)[email protected]

Affected Products

ProductVersions
axios axios
< 0.31.0
>= 1.0.0, < 1.15.0

CPE

  • cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*

Remediation

  • No remediation found in references.

Change History

41 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-40175
NVD Published Date:
Apr 10, 2026
NVD Last Modified:
Sep 9, 2026
Source:
[email protected]
CVE-2026-40175 Details - Not Deferred