CVE-2026-44492

high

Description

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vulnerability is fixed in 0.32.0 and 1.16.0.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44492.json

https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv

https://bugzilla.redhat.com/show_bug.cgi?id=2487938

https://access.redhat.com/security/cve/CVE-2026-44492

https://access.redhat.com/errata/RHSA-2026:33574

https://access.redhat.com/errata/RHSA-2026:33183

https://access.redhat.com/errata/RHSA-2026:33173

https://access.redhat.com/errata/RHSA-2026:33163

https://access.redhat.com/errata/RHSA-2026:33160

https://access.redhat.com/errata/RHSA-2026:33155

https://access.redhat.com/errata/RHSA-2026:33005

https://access.redhat.com/errata/RHSA-2026:30651

https://access.redhat.com/errata/RHSA-2026:30650

https://access.redhat.com/errata/RHSA-2026:29197

https://access.redhat.com/errata/RHSA-2026:29082

https://access.redhat.com/errata/RHSA-2026:28964

https://access.redhat.com/errata/RHSA-2026:27063

https://access.redhat.com/errata/RHSA-2026:27044

https://access.redhat.com/errata/RHSA-2026:26234

https://access.redhat.com/errata/RHSA-2026:20938

https://access.redhat.com/errata/RHSA-2026:20889

Details

Source: Mitre, NVD

Published: 2026-06-11

Updated: 2026-07-02

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 8.6

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.00032