Home / mailings [USN-8638-1] Axios vulnerabilities
Posted on 13 August 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8638-1
August 13, 2026
node-axios vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Axios.
Software Description:
- node-axios: Promise based HTTP client for the browser and node.js
Details:
Ameer Assadi discovered that Axios did not properly handle certain
hostnames when applying NO_PROXY rules. An attacker could possibly use
this issue to bypass proxy restrictions and access internal services,
resulting in server-side request forgery. (CVE-2025-62718)
It was discovered that Axios did not properly protect certain HTTP
header values from prototype pollution. An attacker could possibly use
this issue to inject malicious values into outbound requests, resulting
in HTTP header injection. (CVE-2026-40175)
Sachin Patil and Amol Patil discovered that Axios did not properly apply
NO_PROXY rules to certain loopback addresses. An attacker could possibly
use this issue to bypass proxy restrictions and access internal
services, resulting in server-side request forgery. (CVE-2026-42043)
Yu Bao discovered that Axios did not properly protect JSON response
processing from prototype pollution. An attacker could possibly use this
issue to modify values in application responses, resulting in
authorization bypass or privilege escalation. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-42044)
It was discovered that Axios did not properly protect certain request
configuration options from prototype pollution. An attacker could
possibly use this issue to modify outbound HTTP requests, resulting in
security restrictions being bypassed. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-42264)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
node-axios 1.13.2+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
node-axios 1.6.8+dfsg-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
node-axios 0.26.0+dfsg-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
node-axios 0.19.0+dfsg-2ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8638-1
CVE-2025-62718, CVE-2026-40175, CVE-2026-42043, CVE-2026-42044,
CVE-2026-42264
--===============4337901615392670025==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
