Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-67316— axios before 1.18.0 Prototype Pollution via bodyless methods

Quick assessment

Affected
axios axios
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Axios是Axios团队开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 1.18.0之前版本和0.33.0之前版本存在输入验证错误漏洞,该漏洞源于原型污染gadgets,当Object.prototype已被污染时,在无请求体方法别名中通过(config

CVSS 6.3 · Medium EPSS 0.42% · P34

Possible ATT&CK Techniques 1 AI

T1552.004 · Private Keys

Affected Version Matrix 4

VendorProduct Version RangeStatus
axios axios 1.0.0< 1.18.0 affected
1.18.0 unaffected
< 0.33.0 affected
0.33.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-67316

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
axios before 1.18.0 Prototype Pollution via bodyless methods
Source: CVE Program / CVE List V5
Vulnerability Description
axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before config normalization, causing an attacker-controlled body to be sent on requests that did not set one. Additional low-level paths, only reachable when calling exported adapters/helpers (e.g. lib/adapters/http.js, unsafe/helpers/resolveConfig.js) directly with plain configs and no own proxy or paramsSerializer, can inherit polluted proxy values (routing requests through an attacker-controlled proxy) or paramsSerializer values (attacker-controlled URL serialization). These low-level gadgets do not reproduce through normal high-level axios calls on 1.15.2+. The issue is fixed in axios 1.18.0 and 0.33.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5
Vulnerability Title
Axios 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Axios是Axios团队开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 1.18.0之前版本和0.33.0之前版本存在输入验证错误漏洞,该漏洞源于原型污染gadgets,当Object.prototype已被污染时,在无请求体方法别名中通过(config || {}).data读取继承数据,可能导致攻击者控制请求正文或通过攻击者控制的代理路由请求。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
axios axios 1.0.0 ~ 1.18.0 -
axios axios 0 ~ 0.33.0 -

II. Public POCs for CVE-2026-67316

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67316

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-67316 (2)

Same Patch Batch · axios · 2026-08-01 · 10 CVEs total

CVE-2026-67320 8.3 HIGH axios before 0.33.0 Prototype Pollution via Node HTTP adapter
CVE-2026-67315 6.9 MEDIUM axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
CVE-2026-67321 6.9 MEDIUM axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass
CVE-2026-67318 6.3 MEDIUM axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2
CVE-2026-67312 6.3 MEDIUM axios 0.28.0 before 0.33.0 Denial of Service via formToJSON
CVE-2026-67313 6.3 MEDIUM axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON
CVE-2026-67317 6.3 MEDIUM axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream
CVE-2026-67314 6.3 MEDIUM axios before 1.18.0 Prototype Pollution via auth subfields
CVE-2026-67319 6.3 MEDIUM axios before 0.33.0 Prototype Pollution via nested option objects

IV. Related Vulnerabilities

V. Comments for CVE-2026-67316

No comments yet


Leave a comment