Junglewise Threat Intelligence

CVE-2026-40175: Axios header injection via prototype pollution gadget

CVE-2026-40175 · Severity: high · CVSS 4.8 · Published 2026-04-10

Technologies: Axios. Vendors: Axios, Siemens.

Executive brief

Axios, a widely used tool for making web requests in JavaScript applications, is vulnerable to a security flaw that could allow attackers to manipulate web traffic. By exploiting a weakness in how Axios handles data from other components, an attacker could potentially steal sensitive cloud credentials or gain unauthorized access to internal systems. This could lead to a full compromise of cloud environments like AWS or the execution of malicious code on the server.

Technical details

Axios versions prior to 1.15.0 and 0.31.0 are vulnerable to a 'gadget' attack chain. The vulnerability occurs when prototype pollution in a third-party dependency is used to inject unsanitized header values into outbound HTTP requests. This can be escalated to achieve Server-Side Request Forgery (SSRF), specifically bypassing AWS IMDSv2 protections to exfiltrate cloud metadata, or potentially achieving Remote Code Execution (RCE). The attack requires a precondition of a prototype pollution vulnerability existing elsewhere in the application's dependency tree. Patches are available in versions 1.15.0 and 0.31.0.

Affected products

  • Axios Axios < 1.15.0, < 0.31.0

Timeline

  • 2026-04-10: advisory: Initial publication date
  • 2026-04-06: patched: Fix for cloud metadata exfiltration committed
  • 2026-04-11: patched: Backported fixes committed to v0.x branch

References

Related threats