High severity7.5NVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-44487
CVE-2026-44487
Description
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy. This vulnerability is fixed in 0.32.0 and 1.16.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
axiosnpm | >= 1.0.0, < 1.16.0 | 1.16.0 |
axiosnpm | < 0.32.0 | 0.32.0 |
Affected products
30- osv-coords28 versionspkg:apk/chainguard/awxpkg:apk/chainguard/katib-earlystoppingpkg:apk/chainguard/katib-suggestion-hyperbandpkg:apk/chainguard/katib-suggestion-hyperoptpkg:apk/chainguard/katib-suggestion-nas-dartspkg:apk/chainguard/katib-suggestion-nas-enaspkg:apk/chainguard/katib-suggestion-optuna-enaspkg:apk/chainguard/katib-suggestion-pbt-enaspkg:apk/chainguard/katib-suggestion-skopt-enaspkg:apk/chainguard/katib-tfevent-metricscollectorpkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/opensearch-dashboards-2pkg:apk/chainguard/opensearch-dashboards-2-fipspkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/wolfi/katib-earlystoppingpkg:apk/wolfi/katib-suggestion-hyperbandpkg:apk/wolfi/katib-suggestion-hyperoptpkg:apk/wolfi/katib-suggestion-nas-dartspkg:apk/wolfi/katib-suggestion-nas-enaspkg:apk/wolfi/katib-suggestion-optuna-enaspkg:apk/wolfi/katib-suggestion-pbt-enaspkg:apk/wolfi/katib-suggestion-skopt-enaspkg:apk/wolfi/katib-tfevent-metricscollectorpkg:apk/wolfi/nextcloud-server-33pkg:apk/wolfi/opensearch-dashboards-2pkg:npm/axios
< 24.6.1-r42+ 27 more
- (no CPE)range: < 24.6.1-r42
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 34.0.1-r1
- (no CPE)range: < 2.19.5-r14
- (no CPE)range: < 2.19.5-r14
- (no CPE)range: < 4.14.5-r5
- (no CPE)range: < 4.14.5-r5
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 2.19.5-r14
- (no CPE)range: >= 1.0.0, < 1.16.0
Patches
Vulnerability mechanics
References
5- github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8vnvdExploitVendor AdvisoryMitigationWEB
- github.com/advisories/GHSA-p92q-9vqr-4j8vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44487ghsaADVISORY
- github.com/axios/axios/releases/tag/v0.32.0ghsaWEB
- github.com/axios/axios/releases/tag/v1.16.0ghsaWEB
News mentions
2- Axios: Nine CVEs Disclosed Together — Prototype Pollution, Proxy Leaks, and Bypasses Fixed in 1.16.0Vypr Intelligence · Jun 11, 2026
- Axios: Four High-Severity Vulnerabilities Disclosed Together on June 4thVypr Intelligence · Jun 4, 2026