CVE-2026-67316 | axios prior 1.18.0/0.33.0 Request Construction/HTTP Adapter resolveConfig.js axios.get/axios.delete/axios.head/axios.options config.data/proxy/paramsSerializer prototype pollution
A vulnerability marked as critical has been reported in axios. This affects the function axios.get/axios.delete/axios.head/axios.options of the file lib/adapters/http.js/unsafe/helpers/resolveConfig.js of the component Request Construction/HTTP Adapter. The manipulation of the argument config.data/proxy/paramsSerializer leads to improperly controlled modification of object prototype attributes.
This vulnerability is uniquely identified as CVE-2026-67316. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More