← All CVEs

CVE-2026-44487

HIGH 8.2

Published 2026-06-11 · Last modified 2026-07-01

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy. This vulnerability is fixed in 0.32.0 and 1.16.0.

ELEVATED IMPACT

Severe if exploited (CVSS 8.2), but no known exploitation and low modeled probability. Patch on a normal cadence.

Exploitation likelihood

0.7%chance of exploitation in 30 days · 48th percentile

○ In CISA KEV ○ Public exploit / PoC

Impact if exploited

8.2CVSS 4.0 · HIGH

  • ConfidentialityHigh
  • IntegrityNone
  • AvailabilityNone

What an attacker needs

  • Access: Reachable over the network — no local access needed
  • Privileges: No account or privileges required
  • User interaction: No user interaction needed
  • Complexity: No special conditions — reliably repeatable
  • Requirements: Specific conditions must be present

✓ lowers the bar for an attacker · ⚠ raises it

Affected

Vendors Axios Red Hat

Products Axios Red Hat Advanced Cluster Management For Kubernetes 2.13 Red Hat Advanced Cluster Security For Kubernetes 4.10 Red Hat Developer Hub 1.9 Red Hat Discovery 2 Red Hat Openshift Container Platform 4.16 Red Hat Openshift Container Platform 4.20 Red Hat Openshift Container Platform 4.21

Weakness (CWE)

  • CWE-201

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Sources: NVD · CVE.org · EPSS