Skip to content
CC-4770

CC-4770

Digital.Nhs.Uk [email protected] (NHS Digital) April 14, 2026

CVE‑2026‑40175 could be used in an attack chain to allow for remote code execution or full cloud compromise

CVE‑2026‑40175 could be used in an attack chain to allow for remote code execution or full cloud compromise

The following platforms are known to be affected:

Proof-of-Concept for CVE-2026-40175

A public proof‑of‑concept exploit has been released demonstrating exploitation of CVE‑2026‑40175 via a chained “gadget” attack.

The NHS England National CSOC assesses that as a proof-of-concept exploit is available, exploitation is highly likely.

Axios has released a security update to address a critical vulnerability in the Axios HTTP client library. Successful exploitation could allow an attacker to escalate prototype pollution in third‑party dependencies into remote code execution or full cloud environment compromise, including credential theft from cloud metadata services.

Affected organisations are strongly encouraged to review the Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain advisory and upgrade to Axios version 1.15.0 or later as soon as possible

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0, the Axios library is vulnerable to a specific "Gadget" attack chain that allows Prototype Pollution in any third-party dependency to be escalated into Remote Code Execution (RCE) or Full Cloud Compromise (via AWS IMDSv2 bypass). This vulnerability is fixed in 1.15.0.

Last edited: 14 April 2026 3:06 pm

Extracted Entities

Attack Types (1)

Platforms (1)

Tools (1)

Vulnerabilities (1)