-
-
Notifications
You must be signed in to change notification settings - Fork 197
Open
Description
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing proto as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5. Mend Note: The description of this vulnerability differs from MITRE.
CVSS 3.1 score: 7.5
CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Date published: 2026-02-09
Remediation: Upgrade to version https://github.com/axios/axios.git - v1.13.5
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels