PatchSiren cyber security CVE debrief
CVE-2026-25639 axios CVE debrief
Axios, a promise-based HTTP client for browser and Node.js, has a vulnerability in its mergeConfig function. This function crashes with a TypeError when configuration objects containing __proto__ as an own property are processed. An attacker can exploit this by providing a malicious configuration object created via JSON.parse(), leading to a complete denial of service. The vulnerability is fixed in versions 0.30.3 and 1.13.5.
- Vendor
- axios
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-09
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-02-09
- Advisory updated
- 2026-09-10
Who should care
Defenders managing systems that use Axios for HTTP requests should assess exposure and prioritize updates to prevent denial-of-service attacks. This includes reviewing configuration object handling, validating __proto__ properties, and ensuring systems are updated to versions 0.30.3 or 1.13.5. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators and platform administrators should
Why it matters
CVE-2026-25639 is a high-severity vulnerability in Axios that can lead to denial of service. Defenders should update Axios versions and validate configuration objects to prevent exploitation.
- Denial of service through configuration object manipulation
- Potential for service disruption
- Need for version updates to 0.30.3 or 1.13.5
- Configuration object validation required
Technical summary
The mergeConfig function in Axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. This can be exploited by providing a malicious configuration object created via JSON.parse(). The vulnerability is fixed in versions 0.30.3 and 1.13.5, and defenders should update Axios versions and validate configuration objects to prevent exploitation. Affected systems should be reviewed for exposure, especially those handling untrusted configuration objects. The vulnerability has a high severity score of 7.5 and can lead to complete denial of service.
Defensive priority
Defenders should prioritize updating Axios to versions 0.30.3 or 1.13.5 to prevent denial-of-service attacks. Systems using Axios for HTTP requests should be reviewed for exposure, especially those handling untrusted configuration objects.
Recommended defensive actions
- Update Axios to version 0.30.3 or 1.13.5
- Review systems using Axios for HTTP requests
- Validate configuration objects for __proto__ properties
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD detail provide information on the vulnerability and its fixes. Official references from GitHub and Red Hat offer additional context and patches. Defenders should verify affected systems, review configuration object handling, and assess potential exposure to denial-of-service attacks. Evidence limits suggest focusing on vendor guidance and configuration validation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-25639 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-25639
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-25639 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25639
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/commit/28c721588c7a77e7503d0a434e016f852c597b57
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/commit/d7ff1409c68168d3057fc3891f911b2b92616f9e
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/pull/7369
[email protected] - Issue Tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/pull/7388
[email protected] - Issue Tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/releases/tag/v0.30.3
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/releases/tag/v1.13.5
[email protected] - Product, Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10184
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.