CVE-2026-40175 - Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain
CVE ID :CVE-2026-40175
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axi...
Related Vulnerabilities
- CVE-2026-30232: Chartbrew is an open-source web application that can connect directly to databases and APIs and use N/A
- CVE-2026-35619: OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endp MEDIUM
- CVE-2026-6033: A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of MEDIUM
- CVE-2026-40153: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in she HIGH
- CVE-2026-35577: Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. P MEDIUM
Related Coverage
Threat Actors