← العودة للجدول
CVE-2026-44495
CVE-2026-44495 — Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to
📅 2026-06-11
🟠 High 🔥 No NVD Exploit iOS CVSS 7

📋 الوصف الكامل

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator.

💻 الأنظمة المتأثرة

Apple iOS | Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-44495

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v0.31.1

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←