CVE-2026-25639
Patch Available.
This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.
Overview
Axios is a promise-based HTTP client for JavaScript applications running in the browser and Node.js. It provides a simple API, flexible request and response interceptors, and built-in support for automatic JSON transformation, request cancellation, and timeouts to simplify communication with APIs and services.
A vulnerability (CVE-2026-25639) has been identified in Axios’s configuration merging logic. When a configuration object contains __proto__ as an own property, mergeConfig incorrectly selects an inherited object as a merge function, triggering a TypeError. Applications passing attacker-controlled configuration to Axios may consequently experience denial of service.
This failure maps to CWE-754 (Improper Check for Unusual or Exceptional Conditions). Axios fails to safely handle a specially named configuration property before invoking its selected merge handler. Malicious input can therefore interrupt request processing and, if the resulting error is unhandled, impair application availability.
Details
Module Info
- Product: Axios
- Affected packages:
axios - Affected versions: >=1.0.0, <1.13.5; <0.30.3
- GitHub repository: https://github.com/axios/axios
- Published packages: https://www.npmjs.com/package/axios
- Package manager: npm
- Fixed in:
- OSS Axios v1.15.1
- OSS Axios v0.31.1
- NES for Axios
Vulnerability Info
This high-severity vulnerability affects applications using Axios that accept user-controlled JSON as request configuration. Axios merges configuration objects before issuing requests. However, an own __proto__ property causes its merging logic to select an inherited object as a function, triggering a TypeError. The Axios advisory assigns a CVSS v3.1 score of 7.5.
An attacker could supply specially crafted JSON that causes configuration merging to fail when passed to Axios. Exploitation depends on the application accepting attacker-controlled configuration, with potential denial of service if the resulting error is not safely handled.
This behavior aligns with CWE-754 (Improper Check for Unusual or Exceptional Conditions). This category covers failures to handle unexpected conditions that can disrupt normal application operation. In Axios, improper handling of a special configuration key can interrupt request processing and impair service availability.
Mitigation
Users of affected Axios packages should apply one of the following mitigations:
- Upgrade to a patched version of the
axiospackage. - Leverage commercial support — HeroDevs provides security support for Axios.
