Improper Check for Unusual or Exceptional Conditions in axios - CVE-2026-25639
Published: February 9, 2026 / Updated: March 18, 2026
Vulnerability identifier: #VU122452
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25639
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within proto Key in mergeConfig. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
axios
Cognos Analytics Mobile (iOS)
Storage Sentinel Anomaly Scan Engine
Cognos Analytics Mobile (Android)
Guardium Data Security Center (GDSC)
watsonx Code Assistant On Prem
Maximo Application Suite - Edge Data Collector
Rational Performance Tester
DevOps Test Performance
Db2 Big SQL
Robotic Process Automation for Cloud Pak
IBM Cloud Pak System
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
Crowd Data Center
Jira Service Management Data Center
IBM Rational Build Forge
IBM Maximo Application Suite
Confluence Data Center
Bamboo Data Center
Jira Software Data Center
Fedora
IBM App Connect Enterprise
IBM Security SOAR
nextcloud
Cognos Analytics Mobile (iOS)
Storage Sentinel Anomaly Scan Engine
Cognos Analytics Mobile (Android)
Guardium Data Security Center (GDSC)
watsonx Code Assistant On Prem
Maximo Application Suite - Edge Data Collector
Rational Performance Tester
DevOps Test Performance
Db2 Big SQL
Robotic Process Automation for Cloud Pak
IBM Cloud Pak System
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
Crowd Data Center
Jira Service Management Data Center
IBM Rational Build Forge
IBM Maximo Application Suite
Confluence Data Center
Bamboo Data Center
Jira Software Data Center
Fedora
IBM App Connect Enterprise
IBM Security SOAR
nextcloud
How to mitigate CVE-2026-25639
Install updates from vendor's website.
axios - update to 1.13.5
Cognos Analytics Mobile (iOS) - update to 1.1.26
Storage Sentinel Anomaly Scan Engine - update to 2.3.0
Cognos Analytics Mobile (Android) - update to 1.1.26
IBM Cloud Pak System - update to 2.3.5.1
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 4.0.18-sc2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Code Assistant On Prem - update to 5.3.1
Crowd Data Center - addressed in versions 6.3.5, 7.1.5
Jira Service Management Data Center - addressed in versions 10.3.20, 11.3.4
IBM Rational Build Forge - update to 8.0.0.30
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.27, 9.0.19, 9.1.9
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Bamboo Data Center - addressed in versions 10.2.18, 12.1.6
Jira Software Data Center - addressed in versions 10.3.20, 11.3.4
DevOps Test Performance - update to 11.0.8
IBM App Connect Enterprise - addressed in versions 12.0.12.24, 13.0.6.2
IBM Security SOAR - update to 51.0.9.1
Db2 Big SQL - update to 8.3.1 patch 4
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
nextcloud - addressed in versions 32.0.6-1.el10_1, 32.0.6-1.el10_2, 32.0.6-1.fc42, 32.0.6-1.fc43, 32.0.6-1.fc44
Cognos Analytics Mobile (iOS) - update to 1.1.26
Storage Sentinel Anomaly Scan Engine - update to 2.3.0
Cognos Analytics Mobile (Android) - update to 1.1.26
IBM Cloud Pak System - update to 2.3.5.1
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 4.0.18-sc2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Code Assistant On Prem - update to 5.3.1
Crowd Data Center - addressed in versions 6.3.5, 7.1.5
Jira Service Management Data Center - addressed in versions 10.3.20, 11.3.4
IBM Rational Build Forge - update to 8.0.0.30
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.27, 9.0.19, 9.1.9
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Bamboo Data Center - addressed in versions 10.2.18, 12.1.6
Jira Software Data Center - addressed in versions 10.3.20, 11.3.4
DevOps Test Performance - update to 11.0.8
IBM App Connect Enterprise - addressed in versions 12.0.12.24, 13.0.6.2
IBM Security SOAR - update to 51.0.9.1
Db2 Big SQL - update to 8.3.1 patch 4
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
nextcloud - addressed in versions 32.0.6-1.el10_1, 32.0.6-1.el10_2, 32.0.6-1.fc42, 32.0.6-1.fc43, 32.0.6-1.fc44
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Axios
- Fedora 43 update for nextcloud
- Fedora 44 update for nextcloud
- Fedora EPEL 10.1 update for nextcloud
- Fedora 42 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- IBM App Connect Enterprise Certified Container update for Axios
- Crowd Data Center update for axios
- IBM Security SOAR update for Axios
- IBM Edge Data Collector update for Axios
- Multiple vulnerabilities in IBM Rational Build Forge
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Maximo Application Suite
- IBM DevOps Test Performance update for Axios
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Automation Assets in IBM Cloud Pak for Integration (CP4I) update for Axios
- Bamboo Data Center update for axios
- Confluence Data Center update for axios
- IBM Robotic Process Automation for Cloud Pak update for Axios
- IBM Big SQL on Cloud Pak for Data update for Axios
- Multiple vulnerabilities in IBM Cognos Analytics Mobile
- IBM Watson Discovery Cartridge update for Axios
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM Cloud Pak System