CVE-2026-44495
Description
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
axiosnpm | >= 1.0.0, < 1.15.2 | 1.15.2 |
axiosnpm | >= 0.19.0, < 0.31.1 | 0.31.1 |
Affected products
43- osv-coords30 versionspkg:apk/chainguard/katib-suggestion-pbt-enaspkg:apk/chainguard/katib-suggestion-hyperbandpkg:apk/wolfi/katib-suggestion-nas-dartspkg:apk/wolfi/nextcloud-server-31pkg:apk/chainguard/katib-suggestion-skopt-enaspkg:apk/chainguard/katib-tfevent-metricscollectorpkg:apk/chainguard/nextcloud-server-31pkg:apk/wolfi/katib-suggestion-optuna-enaspkg:apk/wolfi/nextcloud-server-33pkg:apk/chainguard/redisinsightpkg:apk/chainguard/katib-suggestion-nas-dartspkg:apk/chainguard/katib-suggestion-hyperoptpkg:apk/wolfi/katib-suggestion-pbt-enaspkg:apk/chainguard/katib-earlystoppingpkg:apk/chainguard/nextcloud-server-34pkg:apk/chainguard/katib-suggestion-optuna-enaspkg:apk/chainguard/nextcloud-server-33pkg:apk/chainguard/awxpkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/chainguard/opensearch-dashboards-2pkg:apk/chainguard/opensearch-dashboards-2-fipspkg:apk/wolfi/katib-suggestion-hyperbandpkg:apk/wolfi/katib-earlystoppingpkg:apk/wolfi/katib-suggestion-hyperoptpkg:apk/wolfi/katib-suggestion-nas-enaspkg:apk/wolfi/katib-suggestion-skopt-enaspkg:apk/chainguard/katib-suggestion-nas-enaspkg:apk/wolfi/katib-tfevent-metricscollectorpkg:apk/wolfi/opensearch-dashboards-2
< 0.19.0-r31+ 29 more
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 31.0.14-r5
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 31.0.14-r5
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 3.4.2-r4
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 34.0.1-r1
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 33.0.6-r0
- (no CPE)range: < 24.6.1-r42
- (no CPE)range: < 4.14.5-r5
- (no CPE)range: < 4.14.5-r5
- (no CPE)range: < 2.19.5-r14
- (no CPE)range: < 2.19.5-r14
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 0.19.0-r31
- (no CPE)range: < 2.19.5-r14
- cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:*:*:*:*:*:*:*:*Range: <2.13.9
- cpe:2.3:a:redhat:advanced_cluster_security:*:*:*:*:*:kubernates:*:*Range: <4.10.3
- cpe:2.3:a:redhat:ansible_automation_platform:2.6:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:developer_hub:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_service_mesh:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_virtualization:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
52- github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jwnvdExploitVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:20889nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:20938nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:27044nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:27063nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:27944nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:28964nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:29082nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:29197nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:30650nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:30651nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:33155nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:33160nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:33163nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:33173nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:33183nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:33574nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:34160nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:34374nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36108nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36611nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36754nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36820nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36882nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:36883nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:40262nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:40768nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:40792nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:40795nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:41031nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:41055nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:41064nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:41066nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:41928nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:41951nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:42078nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:42142nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:42146nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:42796nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:43052nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:46885nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:46903nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:50300nvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:53840nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-44495nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdThird Party Advisory
- github.com/advisories/GHSA-3g43-6gmg-66jwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44495ghsaADVISORY
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44495.jsonnvdThird Party Advisory
- access.redhat.com/errata/RHSA-2026:54188nvd
- access.redhat.com/errata/RHSA-2026:54555nvd
- access.redhat.com/errata/RHSA-2026:57191nvd
News mentions
1- Axios: Nine CVEs Disclosed Together — Prototype Pollution, Proxy Leaks, and Bypasses Fixed in 1.16.0Vypr Intelligence · Jun 11, 2026