CVE-2026-44494

EUVD-2026-36257
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, which traverses the prototype chain. Because proxy is not present in Axios defaults, the merged config object has no own proxy property, making it trivially injectable via prototype pollution. Once injected, setProxy() routes all HTTP requests through the attacker's proxy server. This vulnerability is fixed in 1.16.0.
Confused Deputy
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
axiosaxios
1.0.0 ≤
𝑥
< 1.16.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:2.5.20260715-1.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:2.5.20260715-1.el9ap ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.6
1783351002 ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.8
1782157085 ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.9
1783348181 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.11
1783350952 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.13
1782157514 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Management for Kubernetes 2.14
1783451729 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Security 4.9
1779371594 ≤
𝑥
< *
ADP
Red HatRed Hat Advanced Cluster Security for Kubernetes 4.10
1779293013 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.7
1783919486 ≤
𝑥
< *
ADP
Red HatRed Hat Container Native Virtualization 4.13
1782426816 ≤
𝑥
< *
ADP
Red HatRed Hat Container Native Virtualization 4.14
1782356760 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.10
1783448184 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1781187342 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1782761244 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1782166952 ≤
𝑥
< *
ADP
Red HatRed Hat Migration Toolkit 1.8
1783690532 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.14
1782911957 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.15
1782127091 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.16
1782244020 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.16
1782243791 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.19
1782171032 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.20
1782313844 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.20
1784148076 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.21
1781731914 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.21
1784134078 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Container Platform 4.22
1782913451 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Dev Spaces 3.29
1782498475 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Dev Spaces 3.29
1782498792 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 2.6
1781937133 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 2.6
1782287580 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.0
1782201894 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.0
1782201833 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.1
1782201696 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.1
1782201537 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.2
1782201851 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.2
1782201812 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.3
1782231869 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift Service Mesh 3.3
1782201466 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.1
1783750447 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.12
1783751865 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.12
1784353904 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.15
1784351966 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.16
1783955846 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.9
1784125838 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1781174698 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1782253070 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1782243376 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.3
1784105894 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
node-axios
bookworm
vulnerable
bullseye
vulnerable
forky
1.18.0-1
fixed
sid
1.18.0-1
fixed
trixie
no-dsa
References