What is CVE-2026-67314?
CVE-2026-67314 affects axios versions >=1.15.2 and <1.18.0, containing prototype-pollution read-side gadgets in Basic auth handling. If an application is already vulnerable to a separate prototype pollution, this flaw can lead to information disclosure via axios requests. Users are advised to update to the latest version.
Azərbaycanca: CVE-2026-67314 axios kitabxanasının 1.15.2-dən 1.18.0 versiyalarına qədər təsir edən, Basic auth emalında "prototype pollution" oxuma qacetlərini ehtiva edən boşluqdur. Əgər tətbiqiniz artıq ayrıca "prototype pollution" boşluğuna məruz qalırsa, bu, axios sorğuları vasitəsilə məlumat sızmasına səbəb ola bilər. İstifadəçilərə kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which functionality of the axios library was CVE-2026-67314 discovered?
The flaw is related to prototype-pollution read-side gadgets in Basic auth handling.
Under what additional condition can CVE-2026-67314 lead to information disclosure?
If the application is already vulnerable to a separate prototype pollution, this flaw can lead to information disclosure via axios requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.