CVE-2026-25639 - Axios affected by Denial of Service via __proto__ Key in mergeConfig

CVE-2026-25639 - Axios affected by Denial of Service via __proto__ Key in mergeConfig

CVE ID : CVE-2026-25639 Published : Feb. 9, 2026, 9:15 p.m. | 1 hour, 7 minutes ago Description : Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in 1.13.5. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Feb. 9, 2026
Affected Product: Node.js
Impact: denial of service