CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

USN-8638-1: Axios vulnerabilities

unknownCVE-2025-62718CVE-2026-40175CVE-2026-42043CVE-2026-42044CVE-2026-42264
Ameer Assadi discovered that Axios did not properly handle certain hostnames when applying NO_PROXY rules. An attacker could possibly use this issue to bypass proxy restrictions and access internal services, resulting in server-side request forgery. (CVE-2025-62718) It was discovered that Axios did not properly protect certain HTTP header values from prototype pollution. An attacker could possibly use this issue to inject malicious values into outbound requests, resulting in HTTP header injection. (CVE-2026-40175) Sachin Patil and Amol Patil discovered that Axios did not properly apply NO_PROXY rules to certain loopback addresses. An attacker could possibly use this issue to bypass proxy restrictions and access internal services, resulting in server-side request forgery. (CVE-2026-42043) Yu Bao discovered that Axios did not properly protect JSON response processing from prototype pollution. An attacker could possibly use this issue to modify values in application responses, resulting in authorization bypass or privilege escalation. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-42044) It was discovered that Axios did not properly protect certain request configuration options from prototype pollution. An attacker could possibly use this issue to modify outbound HTTP requests, resulting in security restrictions being bypassed. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-42264)

CSIRTS triage

What
Multiple vulnerabilities in Axios HTTP client including improper NO_PROXY rule handling, prototype pollution in HTTP headers and JSON responses, allowing proxy bypass and HTTP header injection.
Who is affected
Applications using affected Axios versions making HTTP requests through proxies or processing untrusted JSON responses.
Urgency
High; SSRF via proxy bypass enables access to internal services; prototype pollution allows header injection; active exploitation possible.
Action
Upgrade Axios to patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Axios

Get an email when a new Axios advisory drops — max one per day, one-click unsubscribe.

Details

Source
Ubuntu Security Notices (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-13
Exploitation
Not in CISA KEV at last sync

Original advisory: https://ubuntu.com/security/notices/USN-8638-1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-62718coverage & exploitation statusNVD · CVE.org
CVE-2026-40175coverage & exploitation statusNVD · CVE.org
CVE-2026-42043coverage & exploitation statusNVD · CVE.org
CVE-2026-42044coverage & exploitation statusNVD · CVE.org
CVE-2026-42264coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Ubuntu Security Notices