ENISA EUVD · EUVD-2026-25588Official EUVD mappingAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.
Official EUVD record ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1955Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1687IBM License Metric Tool: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-1513Kiali für Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Kiali für Red Hat OpenShift Service Mesh ausnutzen, um erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2026-1450IBM App Connect Enterprise (Axios): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260429Security Bulletin 29 Apr 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 29 Apr 2026, published on 29 April 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-40175
Référence CVE CVE-2026-40895
https://www.cve.org/CVERecord?id=CVE-2026-40895
Référence CVE CVE-2026-41238
https://www.cve.org/CVERecord?id=CVE-2026-41238
Référence CVE CVE-2026-41239
https://www.cve.org/CVERecord?id=CVE-2026-41239
Référence CVE CVE-2026-41240
https://www.cve.org/CVERecord?id=CVE-2026-41240
Référence CVE CVE-2026-41305
https://www.cve.org/CVERecord?id=CVE-2026-41305
Référence CVE CVE-2026-41907
https://www.cve.org/CVERecord?id=CVE-2026-41907
Référence CVE CVE-2026-41988
https://www.cve.org/CVERecord?id=CVE-2026-41988
Référence CVE CVE-2026-41989
https://www.cve.org/CVERecord?id=CVE-2026-41989
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41848
Référence CVE CVE-2026-41850
https://www.cve.org/CVERecord?id=CVE-2026-41850
Référence CVE CVE-2026-41851
https://www.cve.org/CVERecord?id=CVE-2026-41851
Référence CVE CVE-2026-41852
https://www.cve.org/CVERecord?id=CVE-2026-41852
Référence CVE CVE-2026-41853
https://www.cve.org/CVERecord?id=CVE-2026-41853
Référence CVE CVE-2026-41854
https://www.cve.org/CVERecord?id=CVE-2026-41854
Référence CVE CVE-2026-41907
https://www.cve.org/CVERecord?id=CVE-2026-41907
Référence CVE CVE-2026-41988
https://www.cve.org/CVERecord?id=CVE-2026-41988
Référence CVE CVE-2026-42027
https://www.cve.org/CVERecord?id=CVE-2026-42027
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41607
Référence CVE CVE-2026-41635
https://www.cve.org/CVERecord?id=CVE-2026-41635
Référence CVE CVE-2026-41691
https://www.cve.org/CVERecord?id=CVE-2026-41691
Référence CVE CVE-2026-41695
https://www.cve.org/CVERecord?id=CVE-2026-41695
Référence CVE CVE-2026-41707
https://www.cve.org/CVERecord?id=CVE-2026-41707
Référence CVE CVE-2026-41711
https://www.cve.org/CVERecord?id=CVE-2026-41711
Référence CVE CVE-2026-41716
https://www.cve.org/CVERecord?id=CVE-2026-41716
Référence CVE CVE-2026-41721
https://www.cve.org/CVERecord?id=CVE-2026-41721
Référence CVE CVE-2026-41901
https://www.cve.org/CVERecord?id=CVE-2026-41901
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41411
Référence CVE CVE-2026-41603
https://www.cve.org/CVERecord?id=CVE-2026-41603
Référence CVE CVE-2026-41680
https://www.cve.org/CVERecord?id=CVE-2026-41680
Référence CVE CVE-2026-42009
https://www.cve.org/CVERecord?id=CVE-2026-42009
Référence CVE CVE-2026-42010
https://www.cve.org/CVERecord?id=CVE-2026-42010
Référence CVE CVE-2026-42011
https://www.cve.org/CVERecord?id=CVE-2026-42011
Référence CVE CVE-2026-42012
https://www.cve.org/CVERecord?id=CVE-2026-42012
Référence CVE CVE-2026-42013
https://www.cve.org/CVERecord?id=CVE-2026-42013
Référence CVE CVE-2026-42015
https://www.cve.org/CVERecord?id=CVE-2026-42015
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41846
Référence CVE CVE-2026-41848
https://www.cve.org/CVERecord?id=CVE-2026-41848
Référence CVE CVE-2026-41850
https://www.cve.org/CVERecord?id=CVE-2026-41850
Référence CVE CVE-2026-41851
https://www.cve.org/CVERecord?id=CVE-2026-41851
Référence CVE CVE-2026-41852
https://www.cve.org/CVERecord?id=CVE-2026-41852
Référence CVE CVE-2026-41907
https://www.cve.org/CVERecord?id=CVE-2026-41907
Référence CVE CVE-2026-41988
https://www.cve.org/CVERecord?id=CVE-2026-41988
Référence CVE CVE-2026-42009
https://www.cve.org/CVERecord?id=CVE-2026-42009
Référence CVE CVE-2026-42010
https://www.cve.org/CVERecord?id=CVE-2026-42010
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassianord?id=CVE-2026-21577
Référence CVE CVE-2026-21579
https://www.cve.org/CVERecord?id=CVE-2026-21579
Référence CVE CVE-2026-2332
https://www.cve.org/CVERecord?id=CVE-2026-2332
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-29145
https://www.cve.org/CVERecord?id=CVE-2026-29145
Référence CVE CVE-2026-29146
https://www.cve.org/CVERecord?id=CVE-2026-29146
Référence CVE CVE-2026-33671
https://www.cve.org/CVERecord?id=CVE-2026-33671
Référence CVE CVE-2026-34043
https://www.cve.org/CVERecord?id=CVE-2026-34043
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-40175
Référence CVE CVE-2026-40181
https://www.cve.org/CVERecord?id=CVE-2026-40181
Référence CVE CVE-2026-40895
https://www.cve.org/CVERecord?id=CVE-2026-40895
Référence CVE CVE-2026-41238
https://www.cve.org/CVERecord?id=CVE-2026-41238
Référence CVE CVE-2026-41239
https://www.cve.org/CVERecord?id=CVE-2026-41239
Référence CVE CVE-2026-41240
https://www.cve.org/CVERecord?id=CVE-2026-41240
Référence CVE CVE-2026-41305
https://www.cve.org/CVERecord?id=CVE-2026-41305
Référence CVE CVE-2026-41907
https://www.cve.org/CVERecord?id=CVE-2026-41907
Référence CVE CVE-2026-41988
https://www.cve.org/CVERecord?id=CVE-2026-41988
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0834Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-31938
Référence CVE CVE-2026-32141
https://www.cve.org/CVERecord?id=CVE-2026-32141
Référence CVE CVE-2026-33228
https://www.cve.org/CVERecord?id=CVE-2026-33228
Référence CVE CVE-2026-33532
https://www.cve.org/CVERecord?id=CVE-2026-33532
Référence CVE CVE-2026-33671
https://www.cve.org/CVERecord?id=CVE-2026-33671
Référence CVE CVE-2026-33672
https://www.cve.org/CVERecord?id=CVE-2026-33672
Référence CVE CVE-2026-33750
https://www.cve.org/CVERecord?id=CVE-2026-33750
Référence CVE CVE-2026-3676
https://www.cve.org/CVERecord?id=CVE-2026-3676
Référence CVE CVE-2026-39892
https://www.cve.org/CVERecord?id=CVE-2026-39892
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-34268
Référence CVE CVE-2026-34282
https://www.cve.org/CVERecord?id=CVE-2026-34282
Référence CVE CVE-2026-34477
https://www.cve.org/CVERecord?id=CVE-2026-34477
Référence CVE CVE-2026-34478
https://www.cve.org/CVERecord?id=CVE-2026-34478
Référence CVE CVE-2026-34479
https://www.cve.org/CVERecord?id=CVE-2026-34479
Référence CVE CVE-2026-34480
https://www.cve.org/CVERecord?id=CVE-2026-34480
Référence CVE CVE-2026-39821
https://www.cve.org/CVERecord?id=CVE-2026-39821
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-40895
https://www.cve.org/CVERecord?id=CVE-2026-40895
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0773Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-29129
Référence CVE CVE-2026-33870
https://www.cve.org/CVERecord?id=CVE-2026-33870
Référence CVE CVE-2026-33871
https://www.cve.org/CVERecord?id=CVE-2026-33871
Référence CVE CVE-2026-34077
https://www.cve.org/CVERecord?id=CVE-2026-34077
Référence CVE CVE-2026-34486
https://www.cve.org/CVERecord?id=CVE-2026-34486
Référence CVE CVE-2026-34487
https://www.cve.org/CVERecord?id=CVE-2026-34487
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-41284
https://www.cve.org/CVERecord?id=CVE-2026-41284
Référence CVE CVE-2026-41293
https://www.cve.org/CVERecord?id=CVE-2026-41293
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42211
https://www.cve.org/CVERecord?id=CVE-2026-42211
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42342
https://www.cve.org/CVERecord?id=CVE-2026-42342
Référence CVE CVE-2026-42498
https://www.cve.org/CVERecord?id=CVE-2026-42498
Référence CVE CVE-2026-42579
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0698Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41205
Référence CVE CVE-2026-41238
https://www.cve.org/CVERecord?id=CVE-2026-41238
Référence CVE CVE-2026-41239
https://www.cve.org/CVERecord?id=CVE-2026-41239
Référence CVE CVE-2026-41240
https://www.cve.org/CVERecord?id=CVE-2026-41240
Référence CVE CVE-2026-41312
https://www.cve.org/CVERecord?id=CVE-2026-41312
Référence CVE CVE-2026-41313
https://www.cve.org/CVERecord?id=CVE-2026-41313
Référence CVE CVE-2026-41314
https://www.cve.org/CVERecord?id=CVE-2026-41314
Référence CVE CVE-2026-41425
https://www.cve.org/CVERecord?id=CVE-2026-41425
Référence CVE CVE-2026-41481
https://www.cve.org/CVERecord?id=CVE-2026-41481
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-013502axios projectのaxiosにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性AxiosはブラウザおよびNode.js向けのPromiseベースのHTTPクライアントです。バージョン1.15.1および0.31.1より前のバージョンでは、Object.prototypeがaxiosがhasOwnPropertyのガードなしに読み取るキーによって他の依存関係により汚染されている場合、攻撃者は(a)アプリケーションが受信する前にすべてのJSONレスポンスを密かに傍受および改ざんでき、または(b)基盤となるHTTPトランスポートを完全に乗っ取り、リクエストの資格情報、ヘッダー、ボディにアクセスできます。この前提条件として、同一プロセス内の別のソースによるプロトタイプ汚染が存在します。この脆弱性はバージョン1.15.1および0.31.1で修正されています。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenAxios versions prior to 1.15.1 and 0.31.1 are vulnerable to prototype pollution attacks that enable attackers to intercept, modify JSON responses, or hijack HTTP requests and responses via polluted configuration properties.
Official advisory ↗