Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-44486— Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection

CVSS 7.5 · High EPSS 0.43% · P34

Affected Version Matrix 2

VendorProductVersion RangeStatus
axiosaxios>= 1.0.0, < 1.16.0affected
< 0.32.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-44486

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection
Source: NVD (National Vulnerability Database)
Vulnerability Description
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. This affects Node.js's use of Axios with automatic redirects enabled and an authenticated proxy configuration. Browser adapters are not affected. This vulnerability is fixed in 0.32.0 and 1.16.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Axios 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Axios是Axios开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 0.32.0之前版本和1.16.0之前版本存在信息泄露漏洞,该漏洞源于Node.js HTTP适配器在重定向时可能泄露代理凭据,可能导致代理凭据被发送到重定向目标。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
axiosaxios >= 1.0.0, < 1.16.0 -

II. Public POCs for CVE-2026-44486

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 9752 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-44486

登录查看更多情报信息。

Vendor Advisories for CVE-2026-44486 (1)

Same Patch Batch · axios · 2026-06-11 · 9 CVEs total

CVE-2026-444948.7 HIGHAxios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVE-2026-444928.6 HIGHAxios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY
CVE-2026-444887.5 HIGHAxios: Allocation of Resources Without Limits or Throttling in axios
CVE-2026-444967.5 HIGHAxios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection
CVE-2026-444957.0 HIGHAxios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Me
CVE-2026-444904.8 MEDIUMAxios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge fun
CVE-2026-444893.7 LOWAxios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prot
CVE-2026-44487Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect

IV. Related Vulnerabilities

V. Comments for CVE-2026-44486

No comments yet


Leave a comment