Prototype Pollution in Axios 1.0-1.15.1 (default transformResponse)
CVE-2026-42044 Published on April 24, 2026
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver`
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, this.parseReviver), where this is the merged config object. Because parseReviver is not present in Axios defaults, not validated by assertOptions, and not subject to any constraints, a polluted Object.prototype.parseReviver function is called for every key-value pair in every JSON response, allowing the attacker to selectively modify individual values while leaving the rest of the response intact. This vulnerability is fixed in 1.15.2.
Vulnerability Analysis
CVE-2026-42044 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-42044. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Types
What is a Mass Assignment Vulnerability?
The software receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.
CVE-2026-42044 has been classified to as a Mass Assignment vulnerability or weakness.
What is a Prototype Pollution Vulnerability?
The software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
CVE-2026-42044 has been classified to as a Prototype Pollution vulnerability or weakness.
Products Associated with CVE-2026-42044
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42044 are published in these products:
Affected Versions
axios:- Version >= 1.0.0, < 1.15.2 is affected.
- Version 1780917531 and below * is unaffected.
- Version 1780910888 and below * is unaffected.
- Version 1778511348 and below * is unaffected.
- Version 1778383863 and below * is unaffected.
- Version 1778532610 and below * is unaffected.
- Version 1780920979 and below * is unaffected.
- Version 1780556069 and below * is unaffected.
- Version 1783451729 and below * is unaffected.
- Version 1780876734 and below * is unaffected.
- Version 1780600823 and below * is unaffected.
- Version 1779371594 and below * is unaffected.
- Version 1779293013 and below * is unaffected.
- Version 1782917983 and below * is unaffected.
- Version 1779841586 and below * is unaffected.
- Version 1781187342 and below * is unaffected.
- Version 1782761244 and below * is unaffected.
- Version 1779395188 and below * is unaffected.
- Version 1780590717 and below * is unaffected.
- Version 1779814592 and below * is unaffected.
- Version 1779341289 and below * is unaffected.
- Version 1779520355 and below * is unaffected.
- Version 1779520348 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778164208 and below * is unaffected.
- Version 1778163935 and below * is unaffected.
- Version 1778164042 and below * is unaffected.
- Version 1778163792 and below * is unaffected.
- Version 1778163909 and below * is unaffected.
- Version 1778163785 and below * is unaffected.
- Version 1778163986 and below * is unaffected.
- Version 1779822261 and below * is unaffected.
- Version 1779811412 and below * is unaffected.
- Version 1779689392 and below * is unaffected.
- Version 1780891395 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1783955846 and below * is unaffected.
- Version 1779922205 and below * is unaffected.
- Version 1779811473 and below * is unaffected.
- Version 1781181673 and below * is unaffected.
- Version 1781032495 and below * is unaffected.
- Version 1780105179 and below * is unaffected.
- Version 1779971506 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.