Junglewise Threat Intelligence

CVE-2026-42044: Axios Prototype Pollution gadget in parseReviver

CVE-2026-42044 · Severity: medium · CVSS 6.5 · Published 2026-04-24

Technologies: Axios. Vendors: Axios.

Executive brief

Axios, a widely-used HTTP client library, contains a vulnerability in how it parses JSON responses that allows attackers to silently modify response data if Object.prototype has been polluted by another library in the application's dependency chain. An attacker can selectively alter individual JSON values—such as user permissions, account balances, or authentication tokens—while the rest of the response appears normal, enabling privilege escalation and data manipulation without any visible signs of tampering.

Technical details

The vulnerability exists in lib/defaults/index.js:124 where JSON.parse(data, this.parseReviver) is called with a reviver function inherited from Object.prototype. The parseReviver property is not defined in Axios defaults, not validated by assertOptions, and not subject to any constraints, allowing a polluted Object.prototype.parseReviver function to be invoked for every key-value pair in JSON responses. Unlike previous Axios prototype pollution gadgets, this attack is unconstrained (reviver can return any value), allows selective modification (individual keys can be altered while others remain untouched), and is invisible (responses appear structurally intact). The attack requires prototype pollution to occur elsewhere in the dependency tree (via libraries like qs, minimist, or lodash) but requires no direct user input or configuration error. Affected versions are v0.x through v1.15.1; v1.15.2 and later include patches.

Affected products

  • axios axios >=0.0.0, <=1.15.1

Timeline

  • 2026-05-05: disclosed
  • 2026: patched: Fixed in v1.15.2

References

Related threats