Skip to content

Security: Axios vulnerabilities detected in transitive dependency (multiple CVEs) #1096

Description

@rupalsonje

Hi Angular Module Federation maintainers 👋
I’d like to responsibly report a security concern related to Axios being included as a transitive (internal) dependency. The resolved Axios version in the dependency tree appears to fall within ranges affected by multiple known CVEs.
Axios vulnerability listings:
🔗 https://www.cvedetails.com/version-list/19831/54129/1/Axios-Axios.html

The following Axios CVEs are relevant depending on the resolved version:
CVE‑2026‑40175 – Critical
Unrestricted cloud metadata exfiltration via header injection gadget chain; potential RCE / cloud compromise
Affected versions: < 1.15.0
Fixed in: 1.15.0
GitHub Advisory: GHSA-fvcv-3m26-pcqx
CVE‑2026‑25639 – High
Prototype pollution / denial of service due to unsafe mergeConfig handling of proto
Affected versions: < 0.30.3, < 1.13.5
Fixed in: 0.30.3, 1.13.5
CVE‑2026‑39865 – Medium
HTTP/2 session cleanup logic bug leading to client crash (DoS)
Affected versions: < 1.13.2
Fixed in: 1.13.2
CVE‑2025‑58754 – High
Unbounded memory allocation when handling data: URLs, leading to DoS
Affected versions: < 0.30.2, < 1.12.0
Fixed in: 0.30.2, 1.12.0
CVE‑2025‑27152 – Medium
SSRF and credential leakage due to improper handling of absolute URLs with baseURL

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions