THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67316 — axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()),

[NVD] CVE-2026-67316 — axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()),

mednvdPublished 2026-08-01

CVE-2026-67316 CVSS: None Published: 2026-08-01T13:17:01.673

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a separate vulnerability or dependency. In the bodyless method aliases (axios.get(), axios.delete(), axios.head(), axios.options()), inherited data is read via (config || {}).data before co

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67316