CVE-2026-25639
axios axios, Red Hat Ansible Automation Platform 2.6 for RHEL 9, multicluster engine for Kubernetes 2.1
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.
- CVSS
- 7.5
- EPSS
- 2.50% 83.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.10