HTTP response splitting in axios - CVE-2026-40175

 

HTTP response splitting in axios - CVE-2026-40175

Published: May 20, 2026


Vulnerability identifier: #VU131921
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40175
CWE-ID: CWE-113
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP splitting attacks.

The vulnerability exists due to software does not correclty process CRLF character sequences. A remote attacker can send specially crafted request containing CRLF sequence and make the application to send a split HTTP response.

Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.


Affected software

axios
Langflow
IBM Cloud Pak System
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Sterling B2B Integrator
Confluence Data Center
Jira Service Management Data Center
Jira Software Data Center
Jira Service Management Server
IBM Sterling File Gateway
Fedora
Ubuntu
Jira Software Server
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
node-axios (Ubuntu package)
pgadmin4
nextcloud

How to mitigate CVE-2026-40175

Cybersecurity Help is currently unaware of any official solution to address this vulnerability..

axios - addressed in versions 0.3.1, 1.15.0
Langflow - update to 1.9.0
IBM Cloud Pak System - update to 2.3.5.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.20-sc2, 4.3.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
IBM Spectrum Control - update to 5.5
IBM Sterling File Gateway - update to 6.2.2.1
IBM Sterling B2B Integrator - update to 6.2.2.1
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Jira Software Server - addressed in versions 10.3.22, 11.3.7
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Jira Service Management Server - addressed in versions 10.3.22, 11.3.7
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
node-axios (Ubuntu package) - addressed in versions 0.19.0+dfsg-2ubuntu0.1~esm1, 0.26.0+dfsg-1ubuntu0.1~esm1, 1.6.8+dfsg-2ubuntu0.1~esm1, 1.13.2+dfsg-1ubuntu0.1~esm1
Maximo Scheduler Optimizer - addressed in versions 8.4.28, 8.5.28, 9.0.22, 9.1.11
pgadmin4 - addressed in versions 9.14-3.fc42, 9.14-3.fc43, 9.14-3.fc44
nextcloud - addressed in versions 33.0.3-1.el10_2, 33.0.3-1.el10_3, 33.0.3-1.fc42, 33.0.3-1.fc43, 33.0.3-1.fc44

External References

Related Security Bulletins