HTTP response splitting in axios - CVE-2026-40175
Published: May 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP splitting attacks.
The vulnerability exists due to software does not correclty process CRLF character sequences. A remote attacker can send specially crafted request containing CRLF sequence and make the application to send a split HTTP response.
Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.
Affected software
Langflow
Storage Sentinel Anomaly Scan Engine
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
QRadar Threat Intelligence
QRadar Deployment Intelligence App
Maximo Scheduler Optimizer
IBM Cloud Pak System
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM Sterling B2B Integrator
Confluence Data Center
Jira Software Data Center
Jira Service Management Data Center
Jira Service Management Server
IBM Business Automation Workflow
IBM Sterling File Gateway
Fedora
Ubuntu
Jira Software Server
node-axios (Ubuntu package)
pgadmin4
nextcloud
How to mitigate CVE-2026-40175
Langflow - update to 1.9.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
IBM Cloud Pak System - update to 2.3.5.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Spectrum Control - update to 5.5
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM Sterling File Gateway - update to 6.2.2.1
IBM Sterling B2B Integrator - update to 6.2.2.1
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Jira Software Server - addressed in versions 10.3.22, 11.3.7
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
Jira Service Management Server - addressed in versions 10.3.22, 11.3.7
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
node-axios (Ubuntu package) - addressed in versions 0.19.0+dfsg-2ubuntu0.1~esm1, 0.26.0+dfsg-1ubuntu0.1~esm1, 1.6.8+dfsg-2ubuntu0.1~esm1, 1.13.2+dfsg-1ubuntu0.1~esm1
QRadar Threat Intelligence - update to 2.6.0
QRadar Deployment Intelligence App - update to 3.0.20
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
pgadmin4 - addressed in versions 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44
External References
- https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c
- https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1
- https://github.com/axios/axios/pull/10660
- https://github.com/axios/axios/pull/10688
- https://github.com/axios/axios/releases/tag/v0.31.0
- https://github.com/axios/axios/releases/tag/v1.15.0
- https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
- https://github.com/axios/axios/pull/10660#issuecomment-4224168081
- https://cert-portal.siemens.com/productcert/html/ssa-876049.html
Related Security Bulletins
- HTTP response splitting in Axios
- Fedora 43 update for pgadmin4
- Fedora 42 update for pgadmin4
- Fedora 44 update for pgadmin4
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for Axios
- IBM Maximo Scheduler Optimizer update for Axios
- IBM Watson Discovery Cartridge update for Axios
- Multiple vulnerabilities in Langflow
- Fedora 44 update for nextcloud
- Fedora 43 update for nextcloud
- Fedora EPEL 10.3 update for nextcloud
- Fedora EPEL 10.2 update for nextcloud
- Fedora 42 update for nextcloud
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Spectrum Control
- IBM Sterling B2B Integrator and IBM Sterling File Gateway update for Axios
- Multiple vulnerabilities in Confluence Data Center
- Ubuntu update for node-axios
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Multiple vulnerabilities in IBM QRadar Threat Intelligence