THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-42264 (HIGH 7.4) — Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnPropert

[NVD] CVE-2026-42264 (HIGH 7.4) — Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnPropert

lownvdPublished 2026-05-08

CVE-2026-42264 CVSS: 7.4 HIGH Published: 2026-05-08T04:16:20.313

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype polluti

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-42264