Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
4.8
CVE-2026-40175: Axios can let attackers modify outgoing request headers
CVE-2026-40175 · published 5 months ago
Summary
Versions of the Axios library used in browsers and Node.js before 1.15.0 (or 0.3.1 for older releases) can be tricked into inserting unexpected header data into the requests they send. This could allow an attacker to change how your application communicates with other services. Update Axios to version 1.15.0 or later (or 0.3.1 for the older line) to stop this risk.
What to do
- Update GitHub Actions axios to version 1.15.0.
- Update rootio @rootio/axios to version 1.7.9-root.io.6.
- Update GitHub Actions axios to version 0.31.0.
- Update rootio @rootio/axios to version 1.11.0-root.io.7.
- Update rootio @rootio/axios to version 1.12.1-root.io.4.
- Update rootio @rootio/axios to version 1.13.5-root.io.3.
- Update rootio @rootio/axios to version 1.12.0-root.io.6.
- Update rootio @rootio/axios to version 1.12.1-root.io.6.
- Update rootio @rootio/axios to version 1.13.5-root.io.5.
- Update rootio @rootio/axios to version 1.13.2-root.io.6.
- Update rootio @rootio/axios to version 1.13.6-root.io.3.
- Update GitHub Actions axios to version 1.13.6-aikido.3.
- Update rootio @rootio/axios to version 1.12.1-root.io.13.
- Update GitHub Actions axios to version 1.12.1-aikido.13.
- Update rootio @rootio/axios to version 1.12.1-root.io.15.
- Update GitHub Actions axios to version 1.12.1-aikido.15.
- Update rootio @rootio/axios to version 1.8.4-root.io.7.
- Update GitHub Actions axios to version 1.8.4-aikido.7.
- Update rootio @rootio/axios to version 1.12.0-root.io.9.
- Update GitHub Actions axios to version 1.12.0-aikido.9.
- Update rootio @rootio/axios to version 1.8.4-root.io.8.
- Update GitHub Actions axios to version 1.8.4-aikido.8.
- Update debian node-axios to version 1.15.0-1.
- Update rootio @rootio/axios to version 1.8.4-root.io.9.
- Update GitHub Actions axios to version 1.8.4-aikido.9.
- Update rootio @rootio/axios to version 1.12.0-root.io.10.
- Update GitHub Actions axios to version 1.12.0-aikido.10.
- Update rootio @rootio/axios to version 1.15.0-root.io.12.
- Update GitHub Actions axios to version 1.15.0-aikido.12.
- Update GitHub Actions axios to version 1.15.0-aikido.13.
- Update rootio @rootio/axios to version 1.15.0-root.io.13.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | axios |
< 1.15.0 >= 1.0.0, < 1.15.0 < 0.31.0 Fix: upgrade to 1.15.0
|
| Debian:11 | debian | node-axios | All versions |
| Debian:12 | debian | node-axios | All versions |
| Debian:13 | debian | node-axios | All versions |
| Debian:14 | debian | node-axios |
< 1.15.0-1 Fix: upgrade to 1.15.0-1
|
| Root:npm | rootio | @rootio/axios |
< 1.7.9-root.io.6 < 1.11.0-root.io.7 < 1.12.1-root.io.4 < 1.13.5-root.io.3 < 1.12.0-root.io.6 < 1.12.1-root.io.6 < 1.13.5-root.io.5 < 1.13.2-root.io.6 < 1.13.6-root.io.3 < 1.12.1-root.io.13 < 1.12.1-root.io.15 < 1.8.4-root.io.7 6 more version ranges
Fix: upgrade to 1.7.9-root.io.6
|
| – | axios | axios |
< 1.15.0 < 0.31.0 >= 1.0.0, < 1.15.0 cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:* |
| Root:npm | GitHub Actions | axios |
< 1.13.6-aikido.3 < 1.12.1-aikido.13 < 1.12.1-aikido.15 < 1.8.4-aikido.7 < 1.12.0-aikido.9 < 1.8.4-aikido.8 < 1.8.4-aikido.9 < 1.12.0-aikido.10 < 1.15.0-aikido.12 < 1.15.0-aikido.13 Fix: upgrade to 1.13.6-aikido.3
|
Original advisory text
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-p...
Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.
References
- https://security-tracker.debian.org/tracker/CVE-2026-40175 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:8490
- https://access.redhat.com/errata/RHSA-2026:8491
- https://access.redhat.com/errata/RHSA-2026:8493
- https://access.redhat.com/errata/RHSA-2026:8499
- https://access.redhat.com/errata/RHSA-2026:8500
- https://access.redhat.com/errata/RHSA-2026:8501
- https://access.redhat.com/errata/RHSA-2026:9742
- https://access.redhat.com/security/cve/CVE-2026-40175
- https://github.com/advisories/GHSA-fvcv-3m26-pcqx
- https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1 Patch
- https://github.com/axios/axios/pull/10660 Issue Tracking Patch
- https://github.com/axios/axios/releases/tag/v1.15.0 Product Release Notes
- https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx Exploit Mitigation Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40175 Vendor Advisory
- https://github.com/axios/axios Product
- https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c Patch
- https://github.com/axios/axios/pull/10688 Patch
- https://github.com/axios/axios/releases/tag/v0.31.0 Release Notes
- https://access.redhat.com/errata/RHSA-2026:16874
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40175... Vendor Advisory
- https://github.com/axios/axios/pull/10660#issuecomment-4224168081 Issue Tracking Patch
- https://access.redhat.com/errata/RHSA-2026:10104
- https://access.redhat.com/errata/RHSA-2026:10153
- https://access.redhat.com/errata/RHSA-2026:10172
- https://access.redhat.com/errata/RHSA-2026:10175
- https://access.redhat.com/errata/RHSA-2026:11414
- https://access.redhat.com/errata/RHSA-2026:13542
- https://access.redhat.com/errata/RHSA-2026:13548
- https://access.redhat.com/errata/RHSA-2026:13571
- https://access.redhat.com/errata/RHSA-2026:13826
- https://access.redhat.com/errata/RHSA-2026:14774
- https://access.redhat.com/errata/RHSA-2026:14937
- https://access.redhat.com/errata/RHSA-2026:15091
- https://access.redhat.com/errata/RHSA-2026:17468
- https://access.redhat.com/errata/RHSA-2026:17474
- https://access.redhat.com/errata/RHSA-2026:17657
- https://access.redhat.com/errata/RHSA-2026:17699
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:20041
- https://access.redhat.com/errata/RHSA-2026:20938
- https://access.redhat.com/errata/RHSA-2026:24762
- https://access.redhat.com/errata/RHSA-2026:25041
- https://access.redhat.com/errata/RHSA-2026:36882
- https://access.redhat.com/errata/RHSA-2026:53661
- https://access.redhat.com/errata/RHSA-2026:53676
- https://access.redhat.com/errata/RHSA-2026:53735
- https://access.redhat.com/errata/RHSA-2026:53736
- https://access.redhat.com/errata/RHSA-2026:53752
- https://access.redhat.com/errata/RHSA-2026:53778
- https://access.redhat.com/errata/RHSA-2026:53789
- https://access.redhat.com/errata/RHSA-2026:53799
- https://access.redhat.com/errata/RHSA-2026:53835
- https://access.redhat.com/errata/RHSA-2026:53840
- https://access.redhat.com/errata/RHSA-2026:8483
- https://access.redhat.com/errata/RHSA-2026:8484
- https://bugzilla.redhat.com/show_bug.cgi?id=2457432
- https://cert-portal.siemens.com/productcert/html/ssa-876049.html
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40175.json
Severity
4.8
Medium
CVSS 3.1: 10.0 (NVD)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS 1%
Type
CWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CWE-918Server-Side Request Forgery (SSRF)
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
Timeline
Published10 Apr 2026
Updated25 Sep 2026
First seen10 Apr 2026
Sources
DEBIAN-CVE-2026-40175 · OSV
CVE-2026-40175 · NVD
GHSA-fvcv-3m26-pcqx · GHSA
GHSA-fvcv-3m26-pcqx · OSV
CVE-2026-40175 · MITRE
CVE-2026-40175 · OSV
Track software like this
Free during beta