Axios HTTP Client Prototype Pollution Pre 1.15.1/0.31.1
CVE-2026-42033 Published on April 24, 2026
Axios: Prototype Pollution Gadgets - Response Tampering, Data Exfiltration, and Request Hijacking
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.
Vulnerability Analysis
CVE-2026-42033 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-42033. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Types
What is a Prototype Pollution Vulnerability?
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVE-2026-42033 has been classified to as a Prototype Pollution vulnerability or weakness.
What is a Mass Assignment Vulnerability?
The software receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CVE-2026-42033 has been classified to as a Mass Assignment vulnerability or weakness.
Products Associated with CVE-2026-42033
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42033 are published in these products:
Affected Versions
axios:- Version >= 1.0.0, < 1.15.1 is affected.
- Version < 0.31.1 is affected.
- Version 1780917531 and below * is unaffected.
- Version 1780910888 and below * is unaffected.
- Version 1778511348 and below * is unaffected.
- Version 1778383863 and below * is unaffected.
- Version 1778532610 and below * is unaffected.
- Version 1778508956 and below * is unaffected.
- Version 1778510461 and below * is unaffected.
- Version 1783451729 and below * is unaffected.
- Version 1780876734 and below * is unaffected.
- Version 1780600823 and below * is unaffected.
- Version 1779293013 and below * is unaffected.
- Version 1779371594 and below * is unaffected.
- Version 1779841586 and below * is unaffected.
- Version 1781187342 and below * is unaffected.
- Version 1782761244 and below * is unaffected.
- Version 1778156756 and below * is unaffected.
- Version 1780590717 and below * is unaffected.
- Version 1780467029 and below * is unaffected.
- Version 1780467147 and below * is unaffected.
- Version 1778645099 and below * is unaffected.
- Version 1778539338 and below * is unaffected.
- Version 1779814592 and below * is unaffected.
- Version 1779341289 and below * is unaffected.
- Version 1778191473 and below * is unaffected.
- Version 1778191378 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778164208 and below * is unaffected.
- Version 1778163935 and below * is unaffected.
- Version 1778164042 and below * is unaffected.
- Version 1778163792 and below * is unaffected.
- Version 1778163909 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778163986 and below * is unaffected.
- Version 1779822261 and below * is unaffected.
- Version 1779811412 and below * is unaffected.
- Version 1779689392 and below * is unaffected.
- Version 1780891395 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1779922205 and below * is unaffected.
- Version 1779811473 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
- Version 1781032495 and below * is unaffected.
- Version 1780105179 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.