Report: CVE-2026-40175 - Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain - Complete Guide

Report: CVE-2026-40175 - Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain - Complete Guide

CVE ID :CVE-2026-40175 Published : April 10, 2026, 8:16 p.m. | 1 hour, 28 minutes ago Description :Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific

CVE Details

Published
April 10, 2026
Affected Product: Node.js