Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
4.8

CVE-2026-40175: Axios can let attackers modify outgoing request headers

CVE-2026-40175 · published 5 months ago
Summary

Versions of the Axios library used in browsers and Node.js before 1.15.0 (or 0.3.1 for older releases) can be tricked into inserting unexpected header data into the requests they send. This could allow an attacker to change how your application communicates with other services. Update Axios to version 1.15.0 or later (or 0.3.1 for the older line) to stop this risk.

What to do
  • Update GitHub Actions axios to version 1.15.0.
  • Update rootio @rootio/axios to version 1.7.9-root.io.6.
  • Update GitHub Actions axios to version 0.31.0.
  • Update rootio @rootio/axios to version 1.11.0-root.io.7.
  • Update rootio @rootio/axios to version 1.12.1-root.io.4.
  • Update rootio @rootio/axios to version 1.13.5-root.io.3.
  • Update rootio @rootio/axios to version 1.12.0-root.io.6.
  • Update rootio @rootio/axios to version 1.12.1-root.io.6.
  • Update rootio @rootio/axios to version 1.13.5-root.io.5.
  • Update rootio @rootio/axios to version 1.13.2-root.io.6.
  • Update rootio @rootio/axios to version 1.13.6-root.io.3.
  • Update GitHub Actions axios to version 1.13.6-aikido.3.
  • Update rootio @rootio/axios to version 1.12.1-root.io.13.
  • Update GitHub Actions axios to version 1.12.1-aikido.13.
  • Update rootio @rootio/axios to version 1.12.1-root.io.15.
  • Update GitHub Actions axios to version 1.12.1-aikido.15.
  • Update rootio @rootio/axios to version 1.8.4-root.io.7.
  • Update GitHub Actions axios to version 1.8.4-aikido.7.
  • Update rootio @rootio/axios to version 1.12.0-root.io.9.
  • Update GitHub Actions axios to version 1.12.0-aikido.9.
  • Update rootio @rootio/axios to version 1.8.4-root.io.8.
  • Update GitHub Actions axios to version 1.8.4-aikido.8.
  • Update debian node-axios to version 1.15.0-1.
  • Update rootio @rootio/axios to version 1.8.4-root.io.9.
  • Update GitHub Actions axios to version 1.8.4-aikido.9.
  • Update rootio @rootio/axios to version 1.12.0-root.io.10.
  • Update GitHub Actions axios to version 1.12.0-aikido.10.
  • Update rootio @rootio/axios to version 1.15.0-root.io.12.
  • Update GitHub Actions axios to version 1.15.0-aikido.12.
  • Update GitHub Actions axios to version 1.15.0-aikido.13.
  • Update rootio @rootio/axios to version 1.15.0-root.io.13.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions axios < 1.15.0
>= 1.0.0, < 1.15.0
< 0.31.0
Fix: upgrade to 1.15.0
Debian:11 debian node-axios All versions
Debian:12 debian node-axios All versions
Debian:13 debian node-axios All versions
Debian:14 debian node-axios < 1.15.0-1
Fix: upgrade to 1.15.0-1
Root:npm rootio @rootio/axios < 1.7.9-root.io.6
< 1.11.0-root.io.7
< 1.12.1-root.io.4
< 1.13.5-root.io.3
< 1.12.0-root.io.6
< 1.12.1-root.io.6
< 1.13.5-root.io.5
< 1.13.2-root.io.6
< 1.13.6-root.io.3
< 1.12.1-root.io.13
< 1.12.1-root.io.15
< 1.8.4-root.io.7
6 more version ranges
Fix: upgrade to 1.7.9-root.io.6
– axios axios < 1.15.0
< 0.31.0
>= 1.0.0, < 1.15.0
cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Root:npm GitHub Actions axios < 1.13.6-aikido.3
< 1.12.1-aikido.13
< 1.12.1-aikido.15
< 1.8.4-aikido.7
< 1.12.0-aikido.9
< 1.8.4-aikido.8
< 1.8.4-aikido.9
< 1.12.0-aikido.10
< 1.15.0-aikido.12
< 1.15.0-aikido.13
Fix: upgrade to 1.13.6-aikido.3
Original advisory text
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-p...
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.
References
Severity
4.8 Medium
CVSS 3.1: 10.0 (NVD)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS 1%
Type
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CWE-918Server-Side Request Forgery (SSRF)
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
Timeline
Published10 Apr 2026
Updated25 Sep 2026
First seen10 Apr 2026
Track software like this
Free during beta