ENISA EUVD · EUVD-2026-36257Official EUVD mappingAxios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, which traverses the prototype chain. Because proxy is not present in Axios defaults, the merged config object has no own proxy property, making it trivially injectable via prototype pollution. Once injected, setProxy() routes all HTTP requests through the attacker's proxy server. This vulnerability is fixed in 1.16.0.
Official EUVD record ↗BSI · German · WID-SEC-2026-3307IBM MQ Appliance (Axios Node.js): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM MQ Appliance ausnutzen, um beliebigen Programmcode auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2026-3046IBM Concert: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-2142Red Hat OpenShift Container Platform (protobufjs, fast-uri): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um beliebigen Programmcode auszuführen, um Sicherheitsmaßnahmen zu umgehen und Daten zu manipulieren.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-43951
Référence CVE CVE-2026-44119
https://www.cve.org/CVERecord?id=CVE-2026-44119
Référence CVE CVE-2026-44185
https://www.cve.org/CVERecord?id=CVE-2026-44185
Référence CVE CVE-2026-44186
https://www.cve.org/CVERecord?id=CVE-2026-44186
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44572
https://www.cve.org/CVERecord?id=CVE-2026-44572
Référence CVE CVE-2026-44573
https://www.cve.org/CVERecord?id=CVE-2026-44573
Référence CVE CVE-2026-44576
https://www.cve.org/CVERecord?id=CVE-2026-44576
Référence CVE CVE-2026-44577
https://www.cve.org/CVERecord?id=CVE-2026-44577
Référence CVE CVE-2026-44578
https://www.cve.org/CVERecord?id=CVE-2026-44578
Référence CVE CVE-2026-44580
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-43868
Référence CVE CVE-2026-4410
https://www.cve.org/CVERecord?id=CVE-2026-4410
Référence CVE CVE-2026-44248
https://www.cve.org/CVERecord?id=CVE-2026-44248
Référence CVE CVE-2026-44249
https://www.cve.org/CVERecord?id=CVE-2026-44249
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44598
https://www.cve.org/CVERecord?id=CVE-2026-44598
Référence CVE CVE-2026-45205
https://www.cve.org/CVERecord?id=CVE-2026-45205
Référence CVE CVE-2026-45416
https://www.cve.org/CVERecord?id=CVE-2026-45416
Référence CVE CVE-2026-45623
https://www.cve.org/CVERecord?id=CVE-2026-45623
Référence CVE CVE-2026-45772
https://www.cve.org/CVERecord?id=CVE-2026-45772
Référence CVE CVE-2026-45773
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-44405
Référence CVE CVE-2026-44417
https://www.cve.org/CVERecord?id=CVE-2026-44417
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44489
https://www.cve.org/CVERecord?id=CVE-2026-44489
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44618
https://www.cve.org/CVERecord?id=CVE-2026-44618
Référence CVE CVE-2026-44728
https://www.cve.org/CVERecord?id=CVE-2026-44728
Référence CVE CVE-2026-44930
https://www.cve.org/CVERecord?id=CVE-2026-44930
Référence CVE CVE-2026-44990
https://www.cve.org/CVERecord?id=CVE-2026-44990
Référence CVE CVE-2026-45149
https://www.cve.org/CVERecord?id=CVE-2026-45149
Référence CVE CVE-2026-45249
https://www.cve.org/CVERecord?id=CVE-2026-45249
Référence CVE CVE-2026-4539
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMord?id=CVE-2026-44160
Référence CVE CVE-2026-44161
https://www.cve.org/CVERecord?id=CVE-2026-44161
Référence CVE CVE-2026-4424
https://www.cve.org/CVERecord?id=CVE-2026-4424
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44930
https://www.cve.org/CVERecord?id=CVE-2026-44930
Référence CVE CVE-2026-4519
https://www.cve.org/CVERecord?id=CVE-2026-4519
Référence CVE CVE-2026-45292
https://www.cve.org/CVERecord?id=CVE-2026-45292
Référence CVE CVE-2026-45505
https://www.cve.org/CVERecord?id=CVE-2026-45505
Référence CVE CVE-2026-46595
https://www.cve.org/CVERecord?id=CVE-2026-46595
Référence CVE CVE-2026-46597
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-42198
Référence CVE CVE-2026-42264
https://www.cve.org/CVERecord?id=CVE-2026-42264
Référence CVE CVE-2026-42581
https://www.cve.org/CVERecord?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=CVE-2026-42583
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44705
https://www.cve.org/CVERecord?id=CVE-2026-44705
Référence CVE CVE-2026-46625
https://www.cve.org/CVERecord?id=CVE-2026-46625
Référence CVE CVE-2026-47838
https://www.cve.org/CVERecord?id=CVE-2026-47838
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48779
https://www.cve.org/CVERecord?id=CVE-2026-48779
Référence CVE CVE-2026-6321
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-019700axios projectのaxiosにおける複数の脆弱性AxiosはブラウザとNode.js向けのPromiseベースのHTTPクライアントです。バージョン1.0.0から1.16.0未満のAxiosライブラリは、Prototype Pollutionの"Gadget"攻撃に対して脆弱であり、アプリケーションの依存関係ツリーにおいて任意のObject.prototypeの汚染が発生すると、完全な中間者攻撃(MITM)にまでエスカレートされる可能性があります。これにより、認証情報を含むすべてのHTTPトラフィックを傍受、読み取り、改ざんすることが可能になります。lib/adapters/http.jsの670行目にあるHTTPアダプターは、標準のプロパティアクセスを通じてconfig.proxyを読み取りますが、この動作はプロトタイプチェーンを辿ります。proxyはAxiosのデフォルトには存在しないため、マージされたconfigオブジェクトには自身のproxyプロパティがなく、プロトタイプ汚染経由で容易に注入することが可能です。注入されると、setProxy()がすべてのHTTPリクエストを攻撃者のプロキシサーバー経由にルーティングします。この脆弱性はバージョン1.16.0で修正されました。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenAxios versions 1.0.0 to before 1.16.0 contain a Prototype Pollution gadget in `config.proxy` that escalates Object.prototype pollution into a full Man-in-the-Middle attack, enabling interception and modification of all HTTP traffic including credentials.
Official advisory ↗