← العودة للجدول
CVE-2026-44492
CVE-2026-44492 — Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.
📅 2026-06-11
🟠 High 🔥 No NVD Exploit iOS CVSS 8.6

📋 الوصف الكامل

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4

💻 الأنظمة المتأثرة

Apple iOS | Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-44492

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-44492 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←