Improper Check for Unusual or Exceptional Conditions in axios - CVE-2026-25639

 

Improper Check for Unusual or Exceptional Conditions in axios - CVE-2026-25639

Published: February 9, 2026 / Updated: March 18, 2026


Vulnerability identifier: #VU122452
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25639
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within proto Key in mergeConfig. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

axios
Cognos Analytics Mobile (iOS)
Storage Sentinel Anomaly Scan Engine
Cognos Analytics Mobile (Android)
Guardium Data Security Center (GDSC)
watsonx Code Assistant On Prem
Maximo Application Suite - Edge Data Collector
Rational Performance Tester
DevOps Test Performance
Db2 Big SQL
Robotic Process Automation for Cloud Pak
IBM Cloud Pak System
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
Crowd Data Center
Jira Service Management Data Center
IBM Rational Build Forge
IBM Maximo Application Suite
Confluence Data Center
Bamboo Data Center
Jira Software Data Center
Fedora
IBM App Connect Enterprise
IBM Security SOAR
nextcloud

How to mitigate CVE-2026-25639

Install updates from vendor's website.

axios - update to 1.13.5
Cognos Analytics Mobile (iOS) - update to 1.1.26
Storage Sentinel Anomaly Scan Engine - update to 2.3.0
Cognos Analytics Mobile (Android) - update to 1.1.26
IBM Cloud Pak System - update to 2.3.5.1
Guardium Data Security Center (GDSC) - update to 3.8.8
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 4.0.18-sc2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
watsonx Code Assistant On Prem - update to 5.3.1
Crowd Data Center - addressed in versions 6.3.5, 7.1.5
Jira Service Management Data Center - addressed in versions 10.3.20, 11.3.4
IBM Rational Build Forge - update to 8.0.0.30
IBM Maximo Application Suite - addressed in versions 8.10.36, 8.11.33, 9.0.22, 9.1.11
Maximo Application Suite - Edge Data Collector - addressed in versions 8.11.27, 9.0.19, 9.1.9
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Bamboo Data Center - addressed in versions 10.2.18, 12.1.6
Jira Software Data Center - addressed in versions 10.3.20, 11.3.4
DevOps Test Performance - update to 11.0.8
IBM App Connect Enterprise - addressed in versions 12.0.12.24, 13.0.6.2
IBM Security SOAR - update to 51.0.9.1
Db2 Big SQL - update to 8.3.1 patch 4
Robotic Process Automation for Cloud Pak - addressed in versions 23.0.20.6, 30.0.2
nextcloud - addressed in versions 32.0.6-1.el10_1, 32.0.6-1.el10_2, 32.0.6-1.fc42, 32.0.6-1.fc43, 32.0.6-1.fc44

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins