Axios <1.15.1 Prototype Pollution via validateStatus
CVE-2026-42041 Published on April 24, 2026
Axios: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.
Vulnerability Analysis
CVE-2026-42041 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-42041. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Types
What is an authentification Vulnerability?
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVE-2026-42041 has been classified to as an authentification vulnerability or weakness.
What is a Prototype Pollution Vulnerability?
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVE-2026-42041 has been classified to as a Prototype Pollution vulnerability or weakness.
What is a Mass Assignment Vulnerability?
The software receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CVE-2026-42041 has been classified to as a Mass Assignment vulnerability or weakness.
Products Associated with CVE-2026-42041
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42041 are published in these products:
Affected Versions
axios:- Version >= 1.0.0, < 1.15.1 is affected.
- Version < 0.31.1 is affected.
- Version 1780917531 and below * is unaffected.
- Version 1780910888 and below * is unaffected.
- Version 1778511348 and below * is unaffected.
- Version 1778383863 and below * is unaffected.
- Version 1778532610 and below * is unaffected.
- Version 1778508956 and below * is unaffected.
- Version 1778510461 and below * is unaffected.
- Version 1783451729 and below * is unaffected.
- Version 1780876734 and below * is unaffected.
- Version 1780600823 and below * is unaffected.
- Version 1779371594 and below * is unaffected.
- Version 1779293013 and below * is unaffected.
- Version 1779841586 and below * is unaffected.
- Version 1781187342 and below * is unaffected.
- Version 1782761244 and below * is unaffected.
- Version 1778156756 and below * is unaffected.
- Version 1780590717 and below * is unaffected.
- Version 1780467029 and below * is unaffected.
- Version 1780467147 and below * is unaffected.
- Version 1778645099 and below * is unaffected.
- Version 1778539338 and below * is unaffected.
- Version 1779814592 and below * is unaffected.
- Version 1779341289 and below * is unaffected.
- Version 1778191473 and below * is unaffected.
- Version 1778191378 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778164208 and below * is unaffected.
- Version 1778163935 and below * is unaffected.
- Version 1778164042 and below * is unaffected.
- Version 1778163792 and below * is unaffected.
- Version 1778163909 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778163986 and below * is unaffected.
- Version 1779822261 and below * is unaffected.
- Version 1779811412 and below * is unaffected.
- Version 1779689392 and below * is unaffected.
- Version 1780891395 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1779922205 and below * is unaffected.
- Version 1779811473 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
- Version 1781032495 and below * is unaffected.
- Version 1780105179 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.