CVE-2026-67320
Last modified
CVE-2026-67320 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| axios | axios | >= 0.31.1, < 0.33.0 |
| axios | axios | >= 1.15.2, < 1.18.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-67320?
How severe is CVE-2026-67320?
How do I fix CVE-2026-67320?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67315axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0…6.9
- CVE-2026-67316axios is vulnerable to read-side prototype-pollution gadgets…6.3
- CVE-2026-67317axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLe…6.3
- CVE-2026-67318axios versions >=1.13.0 (Node.js HTTP adapter) fail to enfor…6.3
- CVE-2026-67319axios before 0.33.0 (and 1.x before 1.18.0) can consume inhe…6.3
- CVE-2026-6732A flaw was found in libxml2. This vulnerability occurs when …7.5
- CVE-2026-67321axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0…6.9
- CVE-2026-67322GitPython before 3.1.52 is vulnerable to environment-variabl…8.7
- CVE-2026-67323GitPython before 3.1.51 fails to guard against dangerous Git…8.6
- CVE-2026-67324GitPython 3.1.50 fails to recognize joined short-option form…9.8
- CVE-2026-67325GitPython before 3.1.51 contains an incomplete command injec…8.8
- CVE-2026-67326GitPython before 3.1.50 fails to validate newline characters…7.3
Are you affected by CVE-2026-67320?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
