Impact
Axios versions affected by CVE-2026-25639 can throw a TypeError while merging request configuration when application-controlled config data contains prototype-related keys [S1][S2]. In Node.js services this can become an availability issue if untrusted JSON or tenant-provided settings are passed into Axios request configuration without validation [S2][S3].
Root Cause
The issue is in Axios mergeConfig, which did not safely handle __proto__ as an own property in configuration objects before the fixed releases [S2][S3]. The advisory source labels this as a denial-of-service condition, not proof that every application using Axios is remotely crashable [S2].
Affected Versions
- Axios 0.x releases before 0.30.3 [S2][S3]
- Axios 1.x releases from 1.0.0 through 1.13.4 [S2][S3]
Fixes
Upgrade Axios to 0.30.3, 1.13.5, or a later non-affected release for the active release line [S2][S3]. Regenerate the active lockfile and rebuild every server, worker, browser bundle, container image, and CI cache that installs Axios. Where application code constructs Axios configuration from request bodies, webhooks, job payloads, tenant settings, or plugin input, keep schema validation in place and reject prototype keys before the data reaches Axios config.
Covered by FixVibe
FixVibe's GitHub repo scans flag npm manifests and lockfiles that resolve axios versions in the affected release ranges [S2][S3], with the file, version, advisory IDs and fixed versions.
