Prototype pollution in axios - CVE-2026-44495
Published: May 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute injected code in the Axios request-processing context, disclose sensitive information, tamper with response data, or cause a denial of service.
The vulnerability exists due to improperly controlled modification of object prototype attributes in Axios request config processing and response transformation when handling requests after Object.prototype has been polluted with a crafted transformResponse value. A remote attacker can pollute Object.prototype.transformResponse through a separate prototype-pollution primitive to execute injected code in the Axios request-processing context, disclose sensitive information, tamper with response data, or cause a denial of service.
Exploitation requires a separate vulnerability or equivalent capability to control Object.prototype in the same JavaScript process or browser context before Axios merges or validates the request config. Browser and Node usage can both be affected.
Affected software
IBM Cloud Pak System
Jira Service Management Data Center
Crowd Data Center
IBM SPSS Collaboration and Deployment Services
Confluence Data Center
Bitbucket Data Center
Jira Software Data Center
Bamboo Data Center
IBM MQ Appliance
Red Hat OpenShift Container Platform
JBoss Data Grid
How to mitigate CVE-2026-44495
IBM Cloud Pak System - update to 2.3.5.1
Jira Service Management Data Center - addressed in versions 10.3.22, 11.3.7
Crowd Data Center - update to 7.2.2
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF14
Confluence Data Center - addressed in versions 9.2.22, 10.2.14
IBM MQ Appliance - addressed in versions 9.4.0.26, 9.4.5.3, 10.0.0.5
Bitbucket Data Center - addressed in versions 9.4.21, 10.2.4, 10.3.1
Jira Software Data Center - addressed in versions 10.3.22, 11.3.7
Bamboo Data Center - addressed in versions 10.2.20, 12.1.8
Red Hat OpenShift Container Platform - addressed in versions 4.14.69, 4.16.65, 4.20.30, 4.21.25, 4.22.6
JBoss Data Grid - update to 8.6.2
External References
Related Security Bulletins
- Multiple vulnerabilities in axios
- Multiple vulnerabilities in Jira Service Management Data Center and Jira Service Management Server
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Bamboo Data Center
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in Confluence Data Center
- IBM Cloud Pak System update for Axios
- Multiple vulnerabilities in JBoss Data Grid 8.6
- Multiple vulnerabilities in Crowd Data Center
- Multiple vulnerabilities in IBM MQ Appliance