Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-42264

3 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-42264

3 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-42264

3 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-42264

3 месяца назад

Axios is a promise based HTTP client for the browser and Node.js. From ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-q8qp-cvcw-x6jj

3 месяца назад

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20919-1

2 месяца назад

Security update for agama-web-ui

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-42264

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

CVSS3: 7.4
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42264

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

CVSS3: 7.4
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42264

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.

CVSS3: 7.4
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-42264

Axios is a promise based HTTP client for the browser and Node.js. From ...

CVSS3: 7.4
1%
Низкий
3 месяца назад
github логотип
GHSA-q8qp-cvcw-x6jj

Axios has prototype pollution read-side gadgets in HTTP adapter that allow credential injection and request hijacking

CVSS3: 7.4
1%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20919-1

Security update for agama-web-ui

2 месяца назад

Уязвимостей на страницу