High [CVE-2026-67314] Outbound Request Tampering via Prototype Pollution in Basic Auth
This high-severity Red Hat Linux advisory covers CVE-2026-67314 affecting Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.14, Red Hat Ansible Automation Platform 2.1.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js).
When an application is already affected by a separate prototype-pollution primitive and makes an axios request with an own auth object that omits the username and/or password properties, axios reads the inherited Object.prototype.username and Object.prototype.password values and uses them to construct an outbound 'Authorization: Basic...' header. axios itself does not pollute prototypes.
The practical impact is outbound request tampering: an attacker who controls the polluted prototype values can inject attacker-chosen Basic auth credentials or replace an existing Authorization header. Credential disclosure is only possible under additional application-specific conditions.
A flaw was found in axios. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Weakness: CWE-915.
Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Ansible Automation Platform 2.1; Red Hat Hardened Images; and 19 more.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
- rhacm2/console-rhel9:1787339249
- rhacm2/console-rhel9:1787339248
- ansible-automation-platform/automation-portal:1788775748
- jaeger-main-2.20.0-0.8.hum1
- grafana13-1-main-13.1.1-0.5.hum1
- grafana13-1-main-13.1.1-0.5.2.hum1
- rhmtc/openshift-migration-ui-rhel8:1789546373
- devspaces/dashboard-rhel9:1789162884
- openshift-service-mesh/kiali-ossmc-rhel9:1787076322
- openshift-service-mesh/kiali-rhel9:1787077108
- openshift-service-mesh/kiali-ossmc-rhel9:1787166293
- openshift-service-mesh/kiali-rhel9:1787165683
- quay/quay-rhel8:1788561841
- quay/quay-rhel8:1788594376
- quay/quay-rhel8:1788593843
- quay/quay-rhel8:1788191755
- quay/quay-rhel9:1789563753
- quay/quay-rhel9:1790690298
- quay/quay-rhel8:1788595574
- satellite/iop-host-inventory-frontend-rhel9:1788322243
- satellite/iop-vulnerability-frontend-rhel9:1789660969
- satellite/iop-host-inventory-frontend-rhel9:1788260941
- satellite/iop-advisor-frontend-rhel9:1789659565
- satellite/iop-vulnerability-frontend-rhel9:1789660983
- RHSA-2026:60390
- RHSA-2026:60388
- RHSA-2026:65118
- RHSA-2026:48758
- RHSA-2026:49714
- RHSA-2026:50826
- RHSA-2026:68681
- RHSA-2026:68754
- RHSA-2026:59566
- RHSA-2026:59583
- RHSA-2026:66084
- RHSA-2026:66523
- RHSA-2026:70267
- RHSA-2026:63307
- RHSA-2026:69255
- RHSA-2026:74511
- RHSA-2026:65514
- RHSA-2026:63373
- RHSA-2026:68765
- RHSA-2026:63355
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
Mitigation
Upgrade to a fixed release: rhacm2/console-rhel9:1787339249, rhacm2/console-rhel9:1787339248, ansible-automation-platform/automation-portal:1788775748, jaeger-main-2.20.0-0.8.hum1, grafana13-1-main-13.1.1-0.5.hum1, grafana13-1-main-13.1.1-0.5.2.hum1. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 2 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.