Axios是Axios团队开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 0.33.0之前版本和1.18.0版本之前的1.x版本存在输入验证错误漏洞,该漏洞源于在JavaScript进程的Object.prototype已被其他组件污染时,未检查嵌套请求选项对象(如auth和paramsSerializer)的自身属性而读取继承属性,可能导致静默注入Authorization: Basic标头或改变查询字符串序列化。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67320 | 8.3 HIGH | axios before 0.33.0 Prototype Pollution via Node HTTP adapter |
| CVE-2026-67315 | 6.9 MEDIUM | axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0 |
| CVE-2026-67321 | 6.9 MEDIUM | axios 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 Denial of Service via maxDepth bypass |
| CVE-2026-67318 | 6.3 MEDIUM | axios 1.13.0 before 1.18.0 maxBodyLength Bypass via HTTP/2 |
| CVE-2026-67312 | 6.3 MEDIUM | axios 0.28.0 before 0.33.0 Denial of Service via formToJSON |
| CVE-2026-67316 | 6.3 MEDIUM | axios before 1.18.0 Prototype Pollution via bodyless methods |
| CVE-2026-67313 | 6.3 MEDIUM | axios 0.28.0 before 1.18.0 Denial of Service via formDataToJSON |
| CVE-2026-67317 | 6.3 MEDIUM | axios 1.7.0 before 1.18.0 maxBodyLength Bypass via ReadableStream |
| CVE-2026-67314 | 6.3 MEDIUM | axios before 1.18.0 Prototype Pollution via auth subfields |
No comments yet