Junglewise Threat Intelligence

CVE-2026-44489: Axios Proxy-Authorization header injection in setProxy

CVE-2026-44489 · Severity: low · CVSS 3.7 · Published 2026-05-29

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a widely used tool for making web requests in JavaScript applications. A security flaw allows attackers to inject unauthorized credentials into web requests if the application is configured to use a proxy server. This could lead to requests being misidentified by the proxy or potentially blocked, though it does not allow the attacker to see the actual data being sent.

Technical details

This vulnerability is a bypass of the fix for GHSA-q8qp-cvcw-x6jj. While the top-level configuration object in Axios 1.15.2 uses a null prototype, nested objects created via 'utils.merge()' (such as 'config.proxy') are still initialized as plain JavaScript objects. These objects inherit from 'Object.prototype', making them vulnerable to prototype pollution. The 'setProxy()' function in 'lib/adapters/http.js' reads properties like 'username' and 'password' without 'hasOwnProperty' checks. If an attacker pollutes 'Object.prototype.username', Axios will automatically construct and inject a 'Proxy-Authorization' header into all proxied requests. This requires a pre-existing prototype pollution vulnerability in the application's dependency tree and the explicit use of a proxy configuration. The issue is fixed in version 1.16.0.

Affected products

  • Axios Axios 1.15.2 to < 1.16.0

Timeline

  • 2026-05-29: advisory: GitHub advisory published
  • 2026-06-11: disclosed: NVD publication date
  • 2026-06-11: patched: Fixed in version 1.16.0

References

Related threats