7.7

CVE-2026-44495

Exploit

Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AxiosAxios SwPlatformnode.js Version >= 0.19.0 < 0.31.1
AxiosAxios SwPlatformnode.js Version >= 1.0.0 < 1.15.2
RedhatAdvanced Cluster Security SwPlatformkubernates Version < 4.10.3
RedhatData Grid Version8.6.2
RedhatDeveloper Hub Version-
RedhatDiscovery Version-
RedhatQuay Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.528
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.7 2.2 5.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
security-advisories@github.com 7 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7 2.2 4.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes

The product receives input from an upstream component that specifies multiple attributes, properties, or fields that are to be initialized or updated in an object, but it does not properly control which attributes can be modified.

CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://bugzilla.redhat.com/show_bug.cgi?id=2487937
Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44495.json
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:20889
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:20938
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:33574
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:29197
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:30651
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:33155
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:33160
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:33163
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:33173
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:33183
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:34374
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:30650
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:27044
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:27063
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:28964
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:29082
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36108
Third Party Advisory
https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
Vendor Advisory
Exploit
https://access.redhat.com/errata/RHSA-2026:27944
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:34160
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-44495
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36820
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36882
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36754
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36883
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:40262
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:36611
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41066
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41031
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41055
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41064
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:42146
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:42078
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:42142
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41928
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:40792
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:40795
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:40768
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:41951
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:42796
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:43052
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:46885
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:46903
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:50300
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:53840
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:54555
https://access.redhat.com/errata/RHSA-2026:57191
https://access.redhat.com/errata/RHSA-2026:54188