CVE-2026-21697: axios4go's Race Condition in Shared HTTP Client Allows Proxy Configuration Leak
axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global defaultClient is mutated during request execution without synchronization, directly modifying the shared http.Client's Transport, Timeout, and CheckRedirect properties. Impacted applications include that that use axios4go with concurrent requests (multiple goroutines, GetAsync, PostAsync, etc.), those where different requests use different proxy configurations, and those that handle sensitive data (authentication credentials, tokens, API keys). Version 0.6.4 fixes this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21697?
CVE-2026-21697 is considered a moderate severity vulnerability due to the potential for race conditions in HTTP client configuration.
How do I fix CVE-2026-21697?
To fix CVE-2026-21697, update axios4go to version 0.6.4 or later to eliminate the race condition.
What type of vulnerability is CVE-2026-21697?
CVE-2026-21697 is a race condition vulnerability affecting the shared HTTP client configuration in axios4go.
Which versions of axios4go are affected by CVE-2026-21697?
CVE-2026-21697 affects all versions of axios4go prior to 0.6.4.
What impact does CVE-2026-21697 have on applications using axios4go?
The impact of CVE-2026-21697 can lead to data corruption and unexpected application behavior due to unsynchronized modifications of the HTTP client's configuration.