Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25639

Опубликовано: 09 фев. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing proto as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:axios:axios:*:*:*:*:*:node.js:*:*
Версия до 1.13.5 (исключая)

EPSS

Процентиль: 16%
0.00051
Низкий

7.5 High

CVSS3

Дефекты

CWE-754

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.

CVSS3: 7.5
redhat
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.

CVSS3: 7.5
debian
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. Prio ...

CVSS3: 7.5
github
около 2 месяцев назад

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость функции mergeConfig() библиотеки axios, позволяющая нарушителю вызвать отказ в обслуживании путем отправки специально сформированного JSON-файла

EPSS

Процентиль: 16%
0.00051
Низкий

7.5 High

CVSS3

Дефекты

CWE-754