Prototype pollution in axios - CVE-2026-44490
Published: May 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to improper input validation in the merge() function in lib/utils.js. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in data manipulation or denial of service (DoS) condition.
Affected software
DataStage on Cloud Pak for Data
Jira Service Management Data Center
Crowd Data Center
IBM SPSS Collaboration and Deployment Services
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
IBM Security SOAR
How to mitigate CVE-2026-44490
DataStage on Cloud Pak for Data - addressed in versions 5.3.1 patch 8, 5.4 patch 5
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.10
Crowd Data Center - update to 7.2.2
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF14
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Bitbucket Data Center - addressed in versions 9.4.21, 10.2.4, 10.3.1
Bamboo Data Center - addressed in versions 10.2.20, 12.1.8
IBM Security SOAR - update to 51.0.10.2
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in axios
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in Confluence Data Center
- Multiple vulnerabilities in IBM Security SOAR
- Multiple vulnerabilities in Crowd Data Center
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data