CVE-2026-67314 | axios up to 1.17.x Basic Auth Subfield resolveConfig.js prototype pollution

SecurityVulns

A vulnerability marked as critical has been reported in axios up to 1.17.x. Affected is an unknown function of the file lib/adapters/http.js/lib/helpers/resolveConfig.js of the component Basic Auth Subfield Handler. Performing a manipulation results in improperly controlled modification of object prototype attributes.

This vulnerability was named CVE-2026-67314. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More