ENISA EUVD · EUVD-2026-36263Official EUVD mappingAxios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. This affects Node.js's use of Axios with automatic redirects enabled and an authenticated proxy configuration. Browser adapters are not affected. This vulnerability is fixed in 0.32.0 and 1.16.0.
Official EUVD record ↗BSI · German · WID-SEC-2026-3307IBM MQ Appliance (Axios Node.js): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM MQ Appliance ausnutzen, um beliebigen Programmcode auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2026-3046IBM Concert: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1955Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-43513
Référence CVE CVE-2026-43514
https://www.cve.org/CVERecord?id=CVE-2026-43514
Référence CVE CVE-2026-43515
https://www.cve.org/CVERecord?id=CVE-2026-43515
Référence CVE CVE-2026-43827
https://www.cve.org/CVERecord?id=CVE-2026-43827
Référence CVE CVE-2026-43828
https://www.cve.org/CVERecord?id=CVE-2026-43828
Référence CVE CVE-2026-43868
https://www.cve.org/CVERecord?id=CVE-2026-43868
Référence CVE CVE-2026-4410
https://www.cve.org/CVERecord?id=CVE-2026-4410
Référence CVE CVE-2026-44248
https://www.cve.org/CVERecord?id=CVE-2026-44248
Référence CVE CVE-2026-44249
https://www.cve.org/CVERecord?id=CVE-2026-44249
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44598
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-44289
Référence CVE CVE-2026-44290
https://www.cve.org/CVERecord?id=CVE-2026-44290
Référence CVE CVE-2026-44291
https://www.cve.org/CVERecord?id=CVE-2026-44291
Référence CVE CVE-2026-44292
https://www.cve.org/CVERecord?id=CVE-2026-44292
Référence CVE CVE-2026-44293
https://www.cve.org/CVERecord?id=CVE-2026-44293
Référence CVE CVE-2026-44294
https://www.cve.org/CVERecord?id=CVE-2026-44294
Référence CVE CVE-2026-44405
https://www.cve.org/CVERecord?id=CVE-2026-44405
Référence CVE CVE-2026-44417
https://www.cve.org/CVERecord?id=CVE-2026-44417
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44489
https://www.cve.org/CVERecord?id=CVE-2026-44489
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44618
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-42508
Référence CVE CVE-2026-42578
https://www.cve.org/CVERecord?id=CVE-2026-42578
Référence CVE CVE-2026-42588
https://www.cve.org/CVERecord?id=CVE-2026-42588
Référence CVE CVE-2026-44024
https://www.cve.org/CVERecord?id=CVE-2026-44024
Référence CVE CVE-2026-44025
https://www.cve.org/CVERecord?id=CVE-2026-44025
Référence CVE CVE-2026-44160
https://www.cve.org/CVERecord?id=CVE-2026-44160
Référence CVE CVE-2026-44161
https://www.cve.org/CVERecord?id=CVE-2026-44161
Référence CVE CVE-2026-4424
https://www.cve.org/CVERecord?id=CVE-2026-4424
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44930
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-42033
Référence CVE CVE-2026-42035
https://www.cve.org/CVERecord?id=CVE-2026-42035
Référence CVE CVE-2026-42041
https://www.cve.org/CVERecord?id=CVE-2026-42041
Référence CVE CVE-2026-42043
https://www.cve.org/CVERecord?id=CVE-2026-42043
Référence CVE CVE-2026-42044
https://www.cve.org/CVERecord?id=CVE-2026-42044
Référence CVE CVE-2026-42198
https://www.cve.org/CVERecord?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=CVE-2026-42583
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44705
https://www.cve.org/CVERecord?id=
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenAxios Node.js HTTP adapter versions prior to 0.32.0 and 1.16.0 can leak proxy credentials via stale Proxy-Authorization headers when following redirects from proxied to non-proxied targets, exposing sensitive authentication data.
Official advisory ↗