Junglewise Threat Intelligence

CVE-2026-67314: axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and

CVE-2026-67314 · Severity: medium · CVSS 6.5 · Published 2026-08-01

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a popular HTTP client library used by JavaScript/Node.js applications to make requests to other services. A flaw allows an attacker who can pollute JavaScript's Object.prototype to inject malicious credentials into outbound HTTP authentication headers. If an application passes an empty or incomplete auth object to axios, the library reads inherited polluted username/password values and uses them to construct Basic auth headers, leading to unauthorized requests to downstream services.

Technical details

This is a prototype pollution read-side gadget vulnerability in axios' Basic auth handling. The root cause is unsafe property access in lib/adapters/http.js and lib/helpers/resolveConfig.js: when an auth object is passed but lacks own username or password properties, axios reads these fields directly (e.g., `configAuth.username || ''`) which walks the prototype chain and inherits polluted Object.prototype values. Exploitation requires two preconditions: (1) the host application must already be vulnerable to prototype pollution via a separate vulnerability, and (2) the axios call must use a pattern like `auth: opts.auth || {}` where the auth object has missing own properties. An attacker who controls Object.prototype.username/password can then inject arbitrary Basic auth credentials, replace existing Authorization headers, or cause downstream auth failures. Patches are available in axios ≥1.18.0 that use utils.hasOwnProp guards to check for own properties before reading subfields.

Affected products

  • axios axios >=1.15.2, <1.18.0

Timeline

  • 2026-07-20: disclosed
  • 2026-07-06: patched: Fix released in v1.18.0

References

Related threats