ENISA EUVD · EUVD-2026-36259Official EUVD mappingAxios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.
Official EUVD record ↗BSI · German · WID-SEC-2026-3307IBM MQ Appliance (Axios Node.js): Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM MQ Appliance ausnutzen, um beliebigen Programmcode auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Denial-of-Service-Zustände herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2026-3046IBM Concert: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-3000Red Hat Enterprise Linux (Apicurio Registry): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (Apicurio Registry) ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen und um einen Cross-Site Scripting Angriff durchzuführen.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2460Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗BSI · German · WID-SEC-2026-1955Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-44185
Référence CVE CVE-2026-44186
https://www.cve.org/CVERecord?id=CVE-2026-44186
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44572
https://www.cve.org/CVERecord?id=CVE-2026-44572
Référence CVE CVE-2026-44573
https://www.cve.org/CVERecord?id=CVE-2026-44573
Référence CVE CVE-2026-44576
https://www.cve.org/CVERecord?id=CVE-2026-44576
Référence CVE CVE-2026-44577
https://www.cve.org/CVERecord?id=CVE-2026-44577
Référence CVE CVE-2026-44578
https://www.cve.org/CVERecord?id=CVE-2026-44578
Référence CVE CVE-2026-44580
https://www.cve.org/CVERecord?id=CVE-2026-44580
Référence CVE CVE-2026-44581
https://www.cve.org/CVERecord?id=CVE-2026-44581
Référence CVE CVE-2026-44582
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-44248
Référence CVE CVE-2026-44249
https://www.cve.org/CVERecord?id=CVE-2026-44249
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44598
https://www.cve.org/CVERecord?id=CVE-2026-44598
Référence CVE CVE-2026-45205
https://www.cve.org/CVERecord?id=CVE-2026-45205
Référence CVE CVE-2026-45416
https://www.cve.org/CVERecord?id=CVE-2026-45416
Référence CVE CVE-2026-45623
https://www.cve.org/CVERecord?id=CVE-2026-45623
Référence CVE CVE-2026-45772
https://www.cve.org/CVERecord?id=CVE-2026-45772
Référence CVE CVE-2026-45773
https://www.cve.org/CVERecord?id=CVE-2026-45773
Référence CVE CVE-2026-45819
https://www.cve.org/CVERecord?id=CVE-2026-45819
Référence CVE CVE-2026-45822
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-44417
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44489
https://www.cve.org/CVERecord?id=CVE-2026-44489
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44618
https://www.cve.org/CVERecord?id=CVE-2026-44618
Référence CVE CVE-2026-44728
https://www.cve.org/CVERecord?id=CVE-2026-44728
Référence CVE CVE-2026-44930
https://www.cve.org/CVERecord?id=CVE-2026-44930
Référence CVE CVE-2026-44990
https://www.cve.org/CVERecord?id=CVE-2026-44990
Référence CVE CVE-2026-45149
https://www.cve.org/CVERecord?id=CVE-2026-45149
Référence CVE CVE-2026-45249
https://www.cve.org/CVERecord?id=CVE-2026-45249
Référence CVE CVE-2026-4539
https://www.cve.org/CVERecord?id=CVE-2026-4539
Référence CVE CVE-2026-45505
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0958Multiples vulnérabilités dans les produits IBMrd?id=CVE-2026-4424
Référence CVE CVE-2026-44431
https://www.cve.org/CVERecord?id=CVE-2026-44431
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44930
https://www.cve.org/CVERecord?id=CVE-2026-44930
Référence CVE CVE-2026-4519
https://www.cve.org/CVERecord?id=CVE-2026-4519
Référence CVE CVE-2026-45292
https://www.cve.org/CVERecord?id=CVE-2026-45292
Référence CVE CVE-2026-45505
https://www.cve.org/CVERecord?id=CVE-2026-45505
Référence CVE CVE-2026-46595
https://www.cve.org/CVERecord?id=CVE-2026-46595
Référence CVE CVE-2026-46597
https://www.cve.org/CVERecord?id=CVE-2026-46597
Référence CVE CVE-2026-46598
https://www.cve.org/CVERecord?id=CVE-2026-46598
Référence CVE CVE-2026-46605
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0934Multiples vulnérabilités dans les produits Atlassiand?id=CVE-2026-42581
Référence CVE CVE-2026-42583
https://www.cve.org/CVERecord?id=CVE-2026-42583
Référence CVE CVE-2026-44486
https://www.cve.org/CVERecord?id=CVE-2026-44486
Référence CVE CVE-2026-44487
https://www.cve.org/CVERecord?id=CVE-2026-44487
Référence CVE CVE-2026-44488
https://www.cve.org/CVERecord?id=CVE-2026-44488
Référence CVE CVE-2026-44490
https://www.cve.org/CVERecord?id=CVE-2026-44490
Référence CVE CVE-2026-44492
https://www.cve.org/CVERecord?id=CVE-2026-44492
Référence CVE CVE-2026-44494
https://www.cve.org/CVERecord?id=CVE-2026-44494
Référence CVE CVE-2026-44495
https://www.cve.org/CVERecord?id=CVE-2026-44495
Référence CVE CVE-2026-44496
https://www.cve.org/CVERecord?id=CVE-2026-44496
Référence CVE CVE-2026-44705
https://www.cve.org/CVERecord?id=CVE-2026-44705
Référence CVE CVE-2026-46625
https://www.cve.org/CVERecord?id=CVE-2026-46625
Référence CVE CVE-2026-47838
https://www.cve.org/CVERecord?id=CVE-2026-47838
Référence CVE CVE-2026-4800
https://www.cve.org/CVERecord?id=CVE-2026-4800
Référence CVE CVE-2026-48779
https://www.cve.org/CVERecord?id=CVE-2026-48779
Référence CVE CVE-2026-6321
https://www.cve.org/CVERecord?id=CVE-2026-6321
Référence CVE CVE-2026-6322
https://www.cve.org/CVERecord?id=CVE-2026-6322
Gestion détaillée du document
le 27 juillet 2026
Version initiale
Al
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-019699axios projectのaxiosにおける複数の脆弱性AxiosはブラウザとNode.js向けのPromiseベースのHTTPクライアントです。0.x系の0.32.0未満および1.x系の1.16.0未満のAxiosバージョンでは、設定されたXSRFクッキー名から正規表現を作成する際に、正規表現のメタキャラクターをエスケープしていません。標準的なブラウザ環境において、axiosに渡されるクッキー名を操作できる攻撃者は、axiosがdocument.cookieを読み込む際に高コストな正規表現のバックトラッキングを引き起こす可能性があります。実際の影響としてはクライアント側の可用性が低下し、axiosがリクエストを準備している間に該当のブラウザタブがフリーズするなどの問題が発生します。この問題は、通常のNode.js HTTPアダプターの使用、React Native、およびaxiosがdocument.cookieを読み込まないWebワーカーには影響を与えません。この脆弱性は0.32.0および1.16.0で修正されています。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenAxios versions before 0.32.0 and 1.16.0 have a vulnerability where unescaped regex metacharacters in the XSRF cookie name cause excessive regex backtracking, leading to client-side denial of service by freezing the browser tab.
Official advisory ↗