Prototype pollution in axios - CVE-2026-67320
Published: July 6, 2026 / Updated: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the Node.js HTTP adapter request path when processing interceptor-returned regular object configs with a polluted Object.prototype.proxy. A remote user can trigger prototype pollution elsewhere in the process and cause affected HTTP requests to be routed through an attacker-controlled proxy to disclose sensitive information.
Exploitation requires Node.js HTTP adapter usage and a request interceptor that returns a plain object copy of the request configuration. The confirmed disclosure impact is limited to plaintext HTTP requests and can expose authorization headers, request metadata, and request body content.
Affected software
Crowd Data Center
Bitbucket Data Center
Bamboo Data Center
How to mitigate CVE-2026-67320
Crowd Data Center - update to 7.2.2
Bitbucket Data Center - addressed in versions 9.4.23, 10.2.6, 10.4.2
Bamboo Data Center - addressed in versions 10.2.22, 12.1.10