← العودة للجدول
CVE-2026-44496
CVE-2026-44496 — Axios is a promise based HTTP client for the browser and Node.js. Axios versions
📅 2026-06-11
🟠 High 🔥 No NVD APT iOS CVSS 7.5

📋 الوصف الكامل

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads

💻 الأنظمة المتأثرة

Apple iOS | Node.js

⚠️ نوع التهديد

APT

🔗 CVE ID

CVE-2026-44496

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v0.32.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←