Prototype pollution in axios - CVE-2026-44490

 

Prototype pollution in axios - CVE-2026-44490

Published: May 29, 2026


Vulnerability identifier: #VU132756
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44490
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to improper input validation in the merge() function in lib/utils.js. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in data manipulation or denial of service (DoS) condition.


Affected software

axios
DataStage on Cloud Pak for Data
Jira Service Management Data Center
Crowd Data Center
IBM SPSS Collaboration and Deployment Services
Confluence Data Center
Bitbucket Data Center
Bamboo Data Center
IBM Security SOAR

How to mitigate CVE-2026-44490

Install updates from vendor's website.

axios - addressed in versions 0.32.0, 1.16.0
DataStage on Cloud Pak for Data - addressed in versions 5.3.1 patch 8, 5.4 patch 5
Jira Service Management Data Center - addressed in versions 10.3.23, 11.3.10
Crowd Data Center - update to 7.2.2
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF14
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
Bitbucket Data Center - addressed in versions 9.4.21, 10.2.4, 10.3.1
Bamboo Data Center - addressed in versions 10.2.20, 12.1.8
IBM Security SOAR - update to 51.0.10.2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins