HTTP response splitting in axios - CVE-2026-40175
Published: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP splitting attacks.
The vulnerability exists due to software does not correclty process CRLF character sequences. A remote attacker can send specially crafted request containing CRLF sequence and make the application to send a split HTTP response.
Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.
Affected software
Langflow
IBM Cloud Pak System
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling B2B Integrator
Confluence Data Center
Jira Service Management Data Center
Jira Software Data Center
Jira Service Management Server
IBM Sterling File Gateway
Fedora
Ubuntu
Jira Software Server
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
node-axios (Ubuntu package)
pgadmin4
nextcloud
How to mitigate CVE-2026-40175
Langflow - update to 1.9.0
IBM Cloud Pak System - update to 2.3.5.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Spectrum Control - update to 5.5
IBM Sterling File Gateway - update to 6.2.2.1
IBM Sterling B2B Integrator - update to 6.2.2.1
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Jira Software Server - addressed in versions 10.3.22, 11.3.7
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Jira Service Management Server - addressed in versions 10.3.22, 11.3.7
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
node-axios (Ubuntu package) - addressed in versions 0.19.0+dfsg-2ubuntu0.1~esm1, 0.26.0+dfsg-1ubuntu0.1~esm1, 1.6.8+dfsg-2ubuntu0.1~esm1, 1.13.2+dfsg-1ubuntu0.1~esm1
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
pgadmin4 - addressed in versions 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
External References
- https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
- https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
- https://github.com/axios/axios/pull/10660
- https://github.com/axios/axios/pull/10688
- https://github.com/axios/axios/releases/tag/v0.31.0
- https://github.com/axios/axios/releases/tag/v1.15.0
- https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
- https://github.com/axios/axios/pull/10660#issuecomment-4224168081
- https://cert-portal.siemens.com/productcert/html/ssa-876049.html
Related Security Bulletins
- HTTP response splitting in Axios
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- Fedora 44 update for pgadmin4
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for Axios
- IBM Maximo Scheduler Optimizer update for Axios
- IBM Watson Discovery Cartridge update for Axios
- Multiple vulnerabilities in Langflow
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Spectrum Control
- IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Axios
- Multiple vulnerabilities in Confluence Data Center
- Ubuntu update for node-axios