CVE-2026-44486

high

Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. This affects Node.js's use of Axios with automatic redirects enabled and an authenticated proxy configuration. Browser adapters are not affected. This vulnerability is fixed in 0.32.0 and 1.16.0.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44486.json

https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc

https://bugzilla.redhat.com/show_bug.cgi?id=2487947

https://access.redhat.com/security/cve/CVE-2026-44486

https://access.redhat.com/errata/RHSA-2026:33574

https://access.redhat.com/errata/RHSA-2026:33183

https://access.redhat.com/errata/RHSA-2026:33173

https://access.redhat.com/errata/RHSA-2026:33163

https://access.redhat.com/errata/RHSA-2026:33160

https://access.redhat.com/errata/RHSA-2026:33155

https://access.redhat.com/errata/RHSA-2026:30651

https://access.redhat.com/errata/RHSA-2026:30650

https://access.redhat.com/errata/RHSA-2026:29197

https://access.redhat.com/errata/RHSA-2026:29082

https://access.redhat.com/errata/RHSA-2026:28964

https://access.redhat.com/errata/RHSA-2026:27063

https://access.redhat.com/errata/RHSA-2026:27044

https://access.redhat.com/errata/RHSA-2026:26234

https://access.redhat.com/errata/RHSA-2026:20938

https://access.redhat.com/errata/RHSA-2026:20889

Details

Source: Mitre, NVD

Published: 2026-06-11

Updated: 2026-07-02

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00031