USN-8638-1: Axios vulnerabilities
Ameer Assadi discovered that Axios did not properly handle certain hostnames when applying NO_PROXY rules. An attacker could possibly use this issue to bypass proxy restrictions and access internal services, resulting in server-side request forgery. (CVE-2025-62718) It was discovered that Axios did not properly protect certain HTTP header values from prototype pollution. An attacker could possibly use this issue to inject malicious values into outbound requests, resulting in HTTP header injection. (CVE-2026-40175) Sachin Patil and Amol Patil discovered that Axios did not properly apply NO_PROXY rules to certain loopback addresses. An attacker could possibly use this issue to bypass proxy restrictions and access internal services, resulting in server-side request forgery. (CVE-2026-42043) Yu Bao discovered that Axios did not properly protect JSON response processing from prototype pollution. An attacker could possibly use this issue to modify values in application responses, resulting in authorization bypass or privilege escalation. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-42044) It was discovered that Axios did not properly protect certain request configuration options from prototype pollution. An attacker could possibly use this issue to modify outbound HTTP requests, resulting in security restrictions being bypassed. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-42264)
CSIRTS triage
- What
- Multiple vulnerabilities in Axios HTTP client including improper NO_PROXY rule handling, prototype pollution in HTTP headers and JSON responses, allowing proxy bypass and HTTP header injection.
- Who is affected
- Applications using affected Axios versions making HTTP requests through proxies or processing untrusted JSON responses.
- Urgency
- High; SSRF via proxy bypass enables access to internal services; prototype pollution allows header injection; active exploitation possible.
- Action
- Upgrade Axios to patched version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Axios
Get an email when a new Axios advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8638-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2025-627181.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 65% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-401751.9% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 78% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-420430.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-420440.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-422640.71% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-62718 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-40175 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42264 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Kiali for Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Multiple vulnerabiliti…cert-bund
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- high[UPDATE] [high] IBM App Connect Enterprise Certified Container: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] IBM App Connect Enterprise (Axios): Multiple vulnerabilitiescert-bund
- high[NEW] [high] IBM DataPower Gateway: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 17, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 3, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (June 26, 2026)cert-fr-avis
More from Ubuntu Security Notices
- unknownUSN-8631-3: Linux kernel (NVIDIA Tegra IGX) vulnerabilities2026-08-13
- unknownUSN-8633-2: Linux kernel vulnerabilities2026-08-13
- unknownUSN-8529-2: Linux kernel vulnerabilities2026-08-13
- unknownUSN-8548-2: Linux kernel vulnerabilities2026-08-13
- unknownUSN-8530-2: Linux kernel (HWE) vulnerabilities2026-08-13