Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-21697

Опубликовано: 07 янв. 2026
Источник: nvd
EPSS Низкий

Описание

axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global defaultClient is mutated during request execution without synchronization, directly modifying the shared http.Client's Transport, Timeout, and CheckRedirect properties. Impacted applications include that that use axios4go with concurrent requests (multiple goroutines, GetAsync, PostAsync, etc.), those where different requests use different proxy configurations, and those that handle sensitive data (authentication credentials, tokens, API keys). Version 0.6.4 fixes this issue.

EPSS

Процентиль: 51%
0.0028
Низкий

Дефекты

CWE-362

EPSS

Процентиль: 51%
0.0028
Низкий

Дефекты

CWE-362