CVE-2026-25639

Denial of Service
Affects
axios
in
Axios
No items found.
Versions
>=1.0.0, <1.13.5; <0.30.3

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Axios is a promise-based HTTP client for JavaScript applications running in the browser and Node.js. It provides a simple API, flexible request and response interceptors, and built-in support for automatic JSON transformation, request cancellation, and timeouts to simplify communication with APIs and services.

A vulnerability (CVE-2026-25639) has been identified in Axios’s configuration merging logic. When a configuration object contains __proto__ as an own property, mergeConfig incorrectly selects an inherited object as a merge function, triggering a TypeError. Applications passing attacker-controlled configuration to Axios may consequently experience denial of service.

This failure maps to CWE-754 (Improper Check for Unusual or Exceptional Conditions). Axios fails to safely handle a specially named configuration property before invoking its selected merge handler. Malicious input can therefore interrupt request processing and, if the resulting error is unhandled, impair application availability.

Details

Module Info

Vulnerability Info

This high-severity vulnerability affects applications using Axios that accept user-controlled JSON as request configuration. Axios merges configuration objects before issuing requests. However, an own __proto__ property causes its merging logic to select an inherited object as a function, triggering a TypeError. The Axios advisory assigns a CVSS v3.1 score of 7.5.

An attacker could supply specially crafted JSON that causes configuration merging to fail when passed to Axios. Exploitation depends on the application accepting attacker-controlled configuration, with potential denial of service if the resulting error is not safely handled.

This behavior aligns with CWE-754 (Improper Check for Unusual or Exceptional Conditions). This category covers failures to handle unexpected conditions that can disrupt normal application operation. In Axios, improper handling of a special configuration key can interrupt request processing and impair service availability.

Mitigation

Users of affected Axios packages should apply one of the following mitigations:

  • Upgrade to a patched version of the axios package.
  • Leverage commercial support — HeroDevs provides security support for Axios.
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2026-25639
PROJECT Affected
axios
Versions Affected
>=1.0.0, <1.13.5; <0.30.3
NES Versions Affected
Published date
September 29, 2026
≈ Fix date
September 1, 2026
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Axios
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.