| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Known vulnerabilities affecting Ios products and systems
| CVE ID | Description | CVSS | Priority | Trend | Exploit | Patch |
|---|---|---|---|---|---|---|
| CVE-2026-42044 | # Vulnerability Disclosure: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` ## Summary The Axios library is vulnerable to a Prototype Pollution "Gadget" attack tha... | 9.1 | 568 | Neutral | No |
| Yes |
| CVE-2026-42043 | **1. Executive Summary** This report documents an **incomplete security patch** for the previously disclosed vulnerability **GHSA-3p68-rc4w-qgx5 (CVE-2025-62718)**, which affects the `NO_PROXY` hostna... | 10.0 | 720 | Neutral | No | Yes |
| CVE-2026-42042 | # Vulnerability Disclosure: XSRF Token Cross-Origin Leakage via Prototype Pollution Gadget in `withXSRFToken` Boolean Coercion ## Summary The Axios library's XSRF token protection logic uses JavaScr... | 5.4 | 121 | Neutral | No | Yes |
| CVE-2026-42041 | # Vulnerability Disclosure: Authentication Bypass via Prototype Pollution Gadget in `validateStatus` Merge Strategy ## Summary The Axios library is vulnerable to a Prototype Pollution "Gadget" attac... | 6.5 | 216 | Neutral | No | Yes |
| CVE-2026-42040 | # Vulnerability Disclosure: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams ## Summary The `encode()` function in `lib/helpers/AxiosURLSearchParams.js` contains a character mapping ... | 3.7 | 102 | Neutral | No | Yes |
| CVE-2026-42039 | ### Summary toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. ### Details lib/helpers/toF... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-42038 | The fix for no_proxy hostname normalization bypass (#10661) is incomplete.When no_proxy=localhost is set, requests to 127.0.0.1 and [::1] still route through the proxy instead of bypassing it. The sh... | 7.5 | 514 | Neutral | No | Yes |
| CVE-2026-42037 | ### Summary The `FormDataPart` constructor in `lib/helpers/formDataToStream.js` interpolates `value.type` directly into the `Content-Type` header of each multipart part without sanitizing CRLF (`\r\n`... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-42036 | ### Summary When responseType: 'stream' is used, Axios returns the response stream without enforcing maxContentLength. This bypasses configured response-size limits and allows unbounded downstream co... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-42035 | ### Summary A prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP headers into outgoing requests. The vulnerability exp... | 7.4 | 442 | Neutral | No | Yes |
| CVE-2026-42034 | ### Summary For stream request bodies, maxBodyLength is bypassed when maxRedirects is set to 0 (native http/https transport path). Oversized streamed uploads are sent fully even when the caller sets ... | 5.3 | 124 | Neutral | No | Yes |
| CVE-2026-42033 | ## Summary When `Object.prototype` has been polluted by any co-dependency with keys that axios reads without a `hasOwnProperty` guard, an attacker can (a) silently intercept and modify every JSON res... | 7.4 | 367 | Neutral | No | Yes |
| CVE-2026-40175 | # Vulnerability Disclosure: Unrestricted Cloud Metadata Exfiltration via Header Injection Chain ## Summary The Axios library is vulnerable to a specific "Gadget" attack chain that allows **Prototype ... | 4.8 | 342 | Low | Yes | Yes |
| CVE-2026-39865 | ### Summary Axios HTTP/2 session cleanup logic contains a state corruption bug that allows a malicious server to crash the client process through concurrent session closures. This denial-of-service v... | 5.9 | 155 | Neutral | No | Yes |
| CVE-2026-25639 | # Denial of Service via **proto** Key in mergeConfig ### Summary The `mergeConfig` function in axios crashes with a TypeError when processing configuration objects containing `__proto__` as an own p... | 7.5 | 386 | Neutral | No | Yes |
| CVE-2026-24858 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 ... | 9.8 | 885 | Neutral | Yes | Yes |
| CVE-2026-22891 | A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead... | 9.8 | 690 | Neutral | Yes | Yes |
| CVE-2026-22153 | An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentl... | 8.1 | 482 | Neutral | No | Yes |
| CVE-2026-21697 | axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaultClient` is mutated during request execut... | 8.1 | 482 | Neutral | No | Yes |
| CVE-2026-20777 | A heap-based buffer overflow vulnerability exists in the Nicolet WFT parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted .wft file can lead to... | 8.1 | 584 | Neutral | Yes | Yes |