ENISA EUVD · EUVD-2026-25606Official EUVD mappingAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.
Official EUVD record ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1687IBM License Metric Tool: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-1513Kiali für Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in Kiali für Red Hat OpenShift Service Mesh ausnutzen, um erweiterte Privilegien zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2026-1450IBM App Connect Enterprise (Axios): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, wodurch weitere Angriffe möglich werden.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260429Security Bulletin 29 Apr 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 29 Apr 2026, published on 29 April 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41989
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42338
https://www.cve.org/CVERecord?id=CVE-2026-42338
Référence CVE CVE-2026-42535
https://www.cve.org/CVERecord?id=CVE-2026-42535
Référence CVE CVE-2026-42536
https://www.cve.org/CVERecord?id=CVE-2026-42536
Référence CVE CVE-2026-43206
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42027
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41901
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=CVE-2026-42404
Référence CVE CVE-2026-42498
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42015
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42253
https://www.cve.org/CVERecord?id=CVE-2026-42253
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42010
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42245
https://www.cve.org/CVERecord?id=CVE-2026-42245
Référence CVE CVE-2026-42246
https://www.cve.org/CVERecord?id=CVE-2026-42246
Référence CVE CVE-2026-42253
https://www.cve.org/CVERecord?id=CVE-2026-42253
Référence CVE CVE-2026-42256
https://www.cve.org/CVERecord?id=CVE-2026-42256
Référence CVE CVE-2026-42257
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassianrd?id=CVE-2026-2332
Référence CVE CVE-2026-29063
https://www.cve.org/CVERecord?id=CVE-2026-29063
Référence CVE CVE-2026-29145
https://www.cve.org/CVERecord?id=CVE-2026-29145
Référence CVE CVE-2026-29146
https://www.cve.org/CVERecord?id=CVE-2026-29146
Référence CVE CVE-2026-33671
https://www.cve.org/CVERecord?id=CVE-2026-33671
Référence CVE CVE-2026-34043
https://www.cve.org/CVERecord?id=CVE-2026-34043
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=CVE-2026-42583
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41988
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42211
https://www.cve.org/CVERecord?id=CVE-2026-42211
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42342
https://www.cve.org/CVERecord?id=CVE-2026-42342
Référence CVE CVE-2026-42502
https://www.cve.org/CVERecord?id=CVE-2026-42502
Référence CVE CVE-2026-42506
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0834Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-39892
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44432
https://www.cve.org/CVERecord?id=CVE-2026-44432
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4923
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-40895
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=CVE-2026-42404
Référence CVE CVE-2026-42502
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0698Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-41481
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42034
https://www.cve.org/CVERecord?id=CVE-2026-42034
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42036
https://www.cve.org/CVERecord?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44432
https://www.cve.org/CVERecord?id=CVE-2026-44432
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4923
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-013494axios projectのaxiosにおける複数の脆弱性AxiosはブラウザとNode.js向けのPromiseベースのHTTPクライアントです。バージョン1.15.1および0.31.1より前のAxiosライブラリには、Prototype Pollution(プロトタイプ汚染)による「ガジェット」攻撃の脆弱性が存在しており、これにより任意のObject.prototypeが汚染されると、HTTPエラー応答(401、403、500など)を静かに抑制して、それらを成功応答として扱うようになります。これにより、アプリケーションレベルの認証およびエラー処理を完全に回避されてしまいます。問題の根本原因は、validateStatusが唯一mergeDirectKeysマージ戦略を使用する設定プロパティであり、この戦略がJavaScriptのin演算子を使用していることにあります。このin演算子はプロトタイプチェーンを横断するため、Object.prototype.validateStatusが() = trueに汚染されると、すべてのHTTPステータスコードが成功として受け入れられてしまいます。この脆弱性はバージョン1.15.1および0.31.1で修正されています。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenAxios versions prior to 1.15.1 and 0.31.1 contain a high-severity Prototype Pollution vulnerability in the validateStatus property merge strategy that allows attackers to bypass authentication and error handling by treating all HTTP error responses as successful.
Official advisory ↗