Medium [CVE-2026-67319] Information disclosure and data manipulation via prototype pollution
This medium-severity Red Hat Linux advisory covers CVE-2026-67319 affecting Red Hat Hardened Images, Gatekeeper 3, Migration Toolkit for Applications 8.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.prototype has already been polluted by another component.
While the top-level merged config uses a null prototype, nested plain objects such as auth and paramsSerializer are cloned into ordinary objects and read without own-property checks.
When an application passes placeholder nested objects such as auth: {} or paramsSerializer: {}, inherited username/password values can cause silent injection of an Authorization: Basic header, and inherited encode/serialize values can alter query-string serialization (full serializer replacement requires a function-valued pollution primitive).
This is exploitable only in the presence of pre-existing prototype pollution. A flaw was found in axios.
When the JavaScript environment's `Object.prototype` has been previously compromised through a technique known as prototype pollution, axios can inadvertently use malicious properties from nested configuration objects. This can lead to the silent injection of unauthorized authentication headers, potentially exposing sensitive credentials.
Additionally, it could allow an attacker to alter how data is formatted for requests, leading to data manipulation.
- < 0.33.0
- < 1.18.0
Official advisory · high-confidence parse· fetched 26 days ago·verify at source
- grafana13-1-main-13.1.1-0.4.hum1
- grafana12-4-main-12.4.6-0.3.hum1
- RHSA-2026:49387
- RHSA-2026:49401
Official advisory · high-confidence parse· fetched 26 days ago·verify at source
Mitigation
Upgrade to a fixed release: grafana13-1-main-13.1.1-0.4.hum1, grafana12-4-main-12.4.6-0.3.hum1, RHSA-2026:49387, RHSA-2026:49401. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 26 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.