axios Improper Neutralization of CRLF Sequences in HTTP Headers (HTTP Request/Response Splitting) Vulnerability - CVE-2026-40175
Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.3.1 the Axios library is vulnerable to a specific quotGadgetquot attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0 and 0.3.1.