Prototype pollution in axios - CVE-2026-44489
Published: May 29, 2026 / Updated: May 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation in "setProxy()" function in lib/adapters/http.js. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in data manipulation.
Affected software
IBM MQ Appliance
IBM Security SOAR
How to mitigate CVE-2026-44489
IBM MQ Appliance - addressed in versions 9.4.0.26, 9.4.5.3, 10.0.0.5
IBM Security SOAR - update to 51.0.10.2