Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44489

Опубликовано: 11 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.username, proxy.password, and proxy.auth without hasOwnProperty checks. When Object.prototype.username is polluted, setProxy() constructs a Proxy-Authorization header with attacker-controlled credentials and injects it into every proxied HTTP request. This vulnerability is fixed in 1.16.0.

A flaw was found in Axios, a promise-based HTTP client. A remote attacker could exploit a prototype pollution vulnerability, which occurs when nested objects are created without proper checks, allowing an attacker to inject malicious properties into Object.prototype. This vulnerability specifically affects the setProxy() function, which, when processing proxy credentials, fails to validate if properties like username or password belong to the object itself. Consequently, attacker-controlled credentials can be injected into Proxy-Authorization headers, potentially leading to information disclosure in proxied HTTP requests.

Отчет

This is a Low impact vulnerability in the Axios HTTP client library. A remote attacker could exploit a prototype pollution flaw to inject arbitrary credentials into the Proxy-Authorization header of proxied HTTP requests. This issue is limited to applications explicitly configured to use a proxy and requires a separate prototype pollution vulnerability within the application's dependency tree, reducing its overall exploitability and impact on confidentiality.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4axiosFix deferred
Cryostat 4cryostat-openshift-console-plugin-npmFix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-ui-rhel8Fix deferred
Migration Toolkit for Applications 8mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf4-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-pf5-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2487940axios: Axios: Information disclosure via Prototype Pollution

EPSS

Процентиль: 14%
0.00228
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.username, proxy.password, and proxy.auth without hasOwnProperty checks. When Object.prototype.username is polluted, setProxy() constructs a Proxy-Authorization header with attacker-controlled credentials and injects it into every proxied HTTP request. This vulnerability is fixed in 1.16.0.

CVSS3: 3.7
nvd
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain. The setProxy() function at lib/adapters/http.js:209-223 reads proxy.username, proxy.password, and proxy.auth without hasOwnProperty checks. When Object.prototype.username is polluted, setProxy() constructs a Proxy-Authorization header with attacker-controlled credentials and injects it into every proxied HTTP request. This vulnerability is fixed in 1.16.0.

CVSS3: 3.7
debian
около 2 месяцев назад

Axios is a promise based HTTP client for the browser and Node.js. From ...

CVSS3: 3.7
github
2 месяца назад

Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix

EPSS

Процентиль: 14%
0.00228
Низкий

3.7 Low

CVSS3