ENISA EUVD · EUVD-2026-28505Official EUVD mappingAxios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.
Official EUVD record ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-2169IBM DataPower Gateway: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Daten zu manipulieren.
Official advisory ↗BSI · German · WID-SEC-2026-1955Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1687IBM License Metric Tool: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM License Metric Tool ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-1654IBM App Connect Enterprise: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM App Connect Enterprise ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren, Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42338
https://www.cve.org/CVERecord?id=CVE-2026-42338
Référence CVE CVE-2026-42535
https://www.cve.org/CVERecord?id=CVE-2026-42535
Référence CVE CVE-2026-42536
https://www.cve.org/CVERecord?id=CVE-2026-42536
Référence CVE CVE-2026-43206
https://www.cve.org/CVERecord?id=CVE-2026-43206
Référence CVE CVE-2026-43828
https://www.cve.org/CVERecord?id=CVE-2026-43828
Référence CVE CVE-2026-43871
https://www.cve.org/CVERecord?id=CVE-2026-43871
Référence CVE CVE-2026-43951
https://www.cve.org/CVERecord?id=CVE-2026-43951
Référence CVE CVE-2026-44119
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1206Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=CVE-2026-42404
Référence CVE CVE-2026-42440
https://www.cve.org/CVERecord?id=CVE-2026-42440
Référence CVE CVE-2026-42577
https://www.cve.org/CVERecord?id=CVE-2026-42577
Référence CVE CVE-2026-42578
https://www.cve.org/CVERecord?id=CVE-2026-42578
Référence CVE CVE-2026-42579
https://www.cve.org/CVERecord?id=CVE-2026-42579
Référence CVE CVE-2026-42580
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=CVE-2026-42404
Référence CVE CVE-2026-42498
https://www.cve.org/CVERecord?id=CVE-2026-42498
Référence CVE CVE-2026-42577
https://www.cve.org/CVERecord?id=CVE-2026-42577
Référence CVE CVE-2026-42578
https://www.cve.org/CVERecord?id=CVE-2026-42578
Référence CVE CVE-2026-42580
https://www.cve.org/CVERecord?id=CVE-2026-42580
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42245
https://www.cve.org/CVERecord?id=CVE-2026-42245
Référence CVE CVE-2026-42246
https://www.cve.org/CVERecord?id=CVE-2026-42246
Référence CVE CVE-2026-42253
https://www.cve.org/CVERecord?id=CVE-2026-42253
Référence CVE CVE-2026-42256
https://www.cve.org/CVERecord?id=CVE-2026-42256
Référence CVE CVE-2026-42257
https://www.cve.org/CVERecord?id=CVE-2026-42257
Référence CVE CVE-2026-42258
https://www.cve.org/CVERecord?id=CVE-2026-42258
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42338
https://www.cve.org/CVERecord?id=CVE-2026-42338
Référence CVE CVE-2026-42502
https://www.cve.org/CVERecord?id=CVE-2026-42502
Référence CVE CVE-2026-42506
https://www.cve.org/CVERecord?id=CVE-2026-42506
Référence CVE CVE-2026-42508
https://www.cve.org/CVERecord?id=CVE-2026-42508
Référence CVE CVE-2026-42578
https://www.cve.org/CVERecord?id=CVE-2026-42578
Référence CVE CVE-2026-42588
https://www.cve.org/CVERecord?id=CVE-2026-42588
Référence CVE CVE-2026-44024
https://www.cve.org/CVERecord?id=CVE-2026-44024
Référence CVE CVE-2026-44025
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-33671
Référence CVE CVE-2026-34043
https://www.cve.org/CVERecord?id=CVE-2026-34043
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=CVE-2026-42583
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0901Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42211
https://www.cve.org/CVERecord?id=CVE-2026-42211
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42342
https://www.cve.org/CVERecord?id=CVE-2026-42342
Référence CVE CVE-2026-42502
https://www.cve.org/CVERecord?id=CVE-2026-42502
Référence CVE CVE-2026-42506
https://www.cve.org/CVERecord?id=CVE-2026-42506
Référence CVE CVE-2026-42508
https://www.cve.org/CVERecord?id=CVE-2026-42508
Référence CVE CVE-2026-44249
https://www.cve.org/CVERecord?id=CVE-2026-44249
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44572
https://www.cve.org/CVERecord?id=CVE-2026-44572
Référence CVE CVE-2026-44573
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0834Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44432
https://www.cve.org/CVERecord?id=CVE-2026-44432
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-4923
https://www.cve.org/CVERecord?id=CVE-2026-4923
Référence CVE CVE-2026-4926
https://www.cve.org/CVERecord?id=CVE-2026-4926
Référence CVE CVE-2026-50645
https://www.cve.org/CVERecord?id=CVE-2026-50645
Référence CVE CVE-2026-6051
https://www.cve.org/CVERecord?id=CVE-2026-6051
Référence CVE CVE-2026-6052
https://www.cve.org/CVERecord?id=CVE-2026-
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0810Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-42036
Référence CVE CVE-2026-42037
https://www.cve.org/CVERecord?id=CVE-2026-42037
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42039
https://www.cve.org/CVERecord?id=CVE-2026-42039
Référence CVE CVE-2026-42040
https://www.cve.org/CVERecord?id=CVE-2026-42040
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42042
https://www.cve.org/CVERecord?id=CVE-2026-42042
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42402
https://www.cve.org/CVERecord?id=CVE-2026-42402
Référence CVE CVE-2026-42403
https://www.cve.org/CVERecord?id=CVE-2026-42403
Référence CVE CVE-2026-42404
https://www.cve.org/CVERecord?id=CVE-2026-42404
Référence CVE CVE-2026-42502
https://www.cve.org/CVERecord?id=CVE-2026-42502
Référence CVE CVE-2026-42506
https://www.cve.org/CVERecord?id=CVE-2026-42506
Référence CVE CVE-2026-42580
https://www.cve.org/CVERecord?id=CVE-2026-42580
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0773Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-34487
Référence CVE CVE-2026-40175
https://www.cve.org/CVERecord?id=CVE-2026-40175
Référence CVE CVE-2026-41284
https://www.cve.org/CVERecord?id=CVE-2026-41284
Référence CVE CVE-2026-41293
https://www.cve.org/CVERecord?id=CVE-2026-41293
Référence CVE CVE-2026-42033
https://www.cve.org/CVERecord?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42038
https://www.cve.org/CVERecord?id=CVE-2026-42038
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42211
https://www.cve.org/CVERecord?id=CVE-2026-42211
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42342
https://www.cve.org/CVERecord?id=CVE-2026-42342
Référence CVE CVE-2026-42498
https://www.cve.org/CVERecord?id=CVE-2026-42498
Référence CVE CVE-2026-42579
https://www.cve.org/CVERecord?id=CVE-2026-42579
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=CVE-2026-42583
Référence CVE CVE-2026-42584
https://www.cve.org/CVERecord?id=CVE-2026-42584
Référence CVE CVE-2026-42585
https://www.cve.org/CVERecord?id=CVE-2026-42585
Référence CVE CVE-2026-42587
https://www.cve.org/CVERecord?id=CVE-2026-42587
Référence CVE CVE-2026-43512
https://www.cve.org/CVERecord?id=
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-015650axios projectのaxiosにおけるオブジェクトプロトタイプ属性の不適切に制御された変更に関する脆弱性AxiosはブラウザとNode.js向けのPromiseベースのHTTPクライアントです。バージョン1.0.0から1.15.2未満の間、HTTPアダプター内の5つの設定プロパティ(auth、baseURL、socketPath、beforeRedirect、およびinsecureHTTPParser)がhasOwnPropertyチェックなしに直接プロパティアクセスされていました。これにより、プロトタイプ汚染のガジェットとして悪用される可能性がありました。同じプロセス内の他の依存関係によってObject.prototypeが汚染されると、axiosはアウトバウンドのHTTPリクエスト毎にこれらの汚染された値を静かに取得してしまいます。この問題はバージョン1.15.2で修正されました。
Official advisory ↗