HTTP Client Proxy Vulnerability in Axios Affects Multiple Versions
CVE-2026-44487

8.2HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
11 June 2026

What is CVE-2026-44487?

The Axios HTTP client has a vulnerability that can lead to the unintended exposure of Proxy-Authorization credentials. In specific scenarios, when Axios processes an authenticated HTTP request through a proxy and subsequently redirects to a new origin without proxying, the proxy credentials may be forwarded to the final destination. This behavior occurs in versions prior to 0.32.0 and 1.16.0, affecting users who rely on secured HTTP communications through proxies. Users are advised to upgrade to the patched versions to mitigate potential security risks.

Affected Version(s)

axios >= 1.0.0, < 1.16.0 < 1.0.0, 1.16.0

axios < 0.32.0 < 0.32.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.