CVE-2026-44495
published 2026-06-11CVE-2026-44495: Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in…
PriorityP354high7.7CVSS 3.1
AVNACHPRNUINSUCHILAH
EPSS
0.84%
55.3th percentile
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.
Affected
72 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | system-rhel7 | — | — |
| 3scale-amp2 | system-rhel8 | — | — |
| 3scale-amp2 | system-rhel9 | — | — |
| 3scale-amp21 | system | — | — |
| 3scale-amp22 | system | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| ansible-automation-platform-26 | gateway-rhel9 | — | — |
| ansible-automation-platform-27 | gateway-rhel9 | — | — |
| ansible-automation-platform | automation-dashboard-rhel9 | — | — |
| ansible-automation-platform | automation-portal | — | — |
| ansible-automation-platform | bootc-automation-portal-rhel9 | — | — |
| apicurio | apicurio-registry-ui-rhel8 | — | — |
| apicurio | apicurio-registry-ui-rhel9 | — | — |
| axios | axios | — | — |
| axios | axios | — | — |
| axios | axios | — | — |
| axios | axios | >= 0.19.0 < 0.31.1 | 0.31.1 |
| axios | axios | >= 0.19.0 < 0.31.1 | 0.31.1 |
| axios | axios | >= 1.0.0 < 1.15.2 | 1.15.2 |
| axios | axios | >= 1.0.0 < 1.15.2 | 1.15.2 |
| container-native-virtualization | kubevirt-console-plugin | — | — |
| container-native-virtualization | kubevirt-console-plugin-rhel9 | — | — |
| devspaces | code-rhel9 | — | — |
| devspaces | dashboard-rhel9 | — | — |
| discovery | discovery-ui-rhel9 | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Axios up to 0.31.0/1.15.1 Configuration code injection
vuldb·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] Axios up to 0.31.0/1.15.1 Configuration code injection
A vulnerability was found in Axios up to 0.31.0/1.15.1. It has been rated as critical. This affects an unknown part of the component Configuration Handler. This manipulation causes code injection.
This vulnerability is registered as CVE-2026-44495. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
ghsa·2026-05-29
CVE-2026-44495 [HIGH] CWE-94 axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
## Summary
Axios versions before the fixed releases contain prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted `Object.prototype.transformResponse`, affected Axios versions may treat that inherited value as request configuration or as an option validator.
Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over `Object.prototype` before Axios creates a request.
## Impact
For ordinary prototype-pollution primitives that can only assign JSON-like values, this issue primarily results in request failur
Red Hat
axios: Axios: Information disclosure due to prototype pollution vulnerability
vendor_redhat·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CWE-915 axios: Axios: Information disclosure due to prototype pollution vulnerability
axios: Axios: Information disclosure due to prototype pollution vulnerability
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.
A flaw was found in Axios, a promise-based HTTP client. This v
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44495 fbthrift: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 fbthrift: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 fbthrift: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 nodejs-aw-webui: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 nodejs-aw-webui: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 nodejs-aw-webui: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 cachelib: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 cachelib: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 cachelib: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 ansible-collection-awx-awx: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 ansible-collection-awx-awx: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
CVE-2026-44495 ansible-collection-awx-awx: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 cachelib: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 cachelib: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
CVE-2026-44495 cachelib: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 oh-my-posh: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 oh-my-posh: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 oh-my-posh: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 boost: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 boost: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 boost: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 magicmirror: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 magicmirror: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 magicmirror: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 h3: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 h3: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 h3: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 fbthrift: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 fbthrift: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
CVE-2026-44495 fbthrift: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
CVE-2026-44495 nextcloud: Axios: Information disclosure due to prototype pollution vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability
CVE-2026-44495 axios: Axios: Information disclosure due to prototype pollution vulnerability
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.
Bugzilla
CVE-2026-44495 magicmirror: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
bugzilla·2026-06-11·CVSS 7.0
CVE-2026-44495 [HIGH] CVE-2026-44495 magicmirror: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
CVE-2026-44495 magicmirror: Axios: Information disclosure due to prototype pollution vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jwhttps://access.redhat.com/errata/RHSA-2026:20889https://access.redhat.com/errata/RHSA-2026:20938https://access.redhat.com/errata/RHSA-2026:27044https://access.redhat.com/errata/RHSA-2026:27063https://access.redhat.com/errata/RHSA-2026:27944https://access.redhat.com/errata/RHSA-2026:28964https://access.redhat.com/errata/RHSA-2026:29082https://access.redhat.com/errata/RHSA-2026:29197https://access.redhat.com/errata/RHSA-2026:30650https://access.redhat.com/errata/RHSA-2026:30651https://access.redhat.com/errata/RHSA-2026:33155https://access.redhat.com/errata/RHSA-2026:33160https://access.redhat.com/errata/RHSA-2026:33163https://access.redhat.com/errata/RHSA-2026:33173https://access.redhat.com/errata/RHSA-2026:33183https://access.redhat.com/errata/RHSA-2026:33574https://access.redhat.com/errata/RHSA-2026:34160https://access.redhat.com/errata/RHSA-2026:34374https://access.redhat.com/errata/RHSA-2026:36108https://access.redhat.com/errata/RHSA-2026:36611https://access.redhat.com/errata/RHSA-2026:36754https://access.redhat.com/errata/RHSA-2026:36820https://access.redhat.com/errata/RHSA-2026:36882https://access.redhat.com/errata/RHSA-2026:36883https://access.redhat.com/errata/RHSA-2026:40262https://access.redhat.com/errata/RHSA-2026:40768https://access.redhat.com/errata/RHSA-2026:40792https://access.redhat.com/errata/RHSA-2026:40795https://access.redhat.com/errata/RHSA-2026:41031https://access.redhat.com/errata/RHSA-2026:41055https://access.redhat.com/errata/RHSA-2026:41064https://access.redhat.com/errata/RHSA-2026:41066https://access.redhat.com/errata/RHSA-2026:41928https://access.redhat.com/errata/RHSA-2026:41951https://access.redhat.com/errata/RHSA-2026:42078https://access.redhat.com/errata/RHSA-2026:42142https://access.redhat.com/errata/RHSA-2026:42146https://access.redhat.com/errata/RHSA-2026:42796https://access.redhat.com/errata/RHSA-2026:43052https://access.redhat.com/errata/RHSA-2026:46885https://access.redhat.com/errata/RHSA-2026:46903https://access.redhat.com/errata/RHSA-2026:50300https://access.redhat.com/errata/RHSA-2026:53840https://access.redhat.com/errata/RHSA-2026:54188https://access.redhat.com/errata/RHSA-2026:54555https://access.redhat.com/errata/RHSA-2026:57191https://access.redhat.com/errata/RHSA-2026:59833https://access.redhat.com/errata/RHSA-2026:60520https://access.redhat.com/security/cve/CVE-2026-44495https://bugzilla.redhat.com/show_bug.cgi?id=2487937https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jwhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44495.json
2026-06-11
Published