Axios CVE-2026-40175: a critical bug that’s… not exploitable
aikido.dev | vulnerability | Medium | CVE-2026-40175 | #prototype-pollution | #request-smuggling | #cve | #ssrf | #vulnerability-analysis | #nodejs | #axios
Summary
Aikido analyzed the 'critical' Axios CVE-2026-40175 gadget chain—prototype pollution to CRLF injection to SSRF—and concluded Node.js blocks CRLF in headers, making it unexploitable in practice.
- CVSS
- 4.8
- Published
- Collected
Skip to content