Axios是Axios开源的一款基于Promise(异步编程的一种解决方案)的HTTP客户端。 Axios 0.32.0之前版本和1.16.0之前版本存在安全漏洞,该漏洞源于存在两个读取侧原型污染小工具,可能导致上游依赖污染Object.prototype后,Axios静默使用污染值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44494 | 8.7 HIGH | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-44492 | 8.6 HIGH | Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY |
| CVE-2026-44487 | 8.2 HIGH | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect |
| CVE-2026-44488 | 7.5 HIGH | Axios: Allocation of Resources Without Limits or Throttling in axios |
| CVE-2026-44496 | 7.5 HIGH | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| CVE-2026-44486 | 7.5 HIGH | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to d |
| CVE-2026-44495 | 7.0 HIGH | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Me |
| CVE-2026-44489 | 3.7 LOW | Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prot |
No comments yet