Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44494 | 8.7 HIGH | Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` |
| CVE-2026-44492 | 8.6 HIGH | Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY |
| CVE-2026-44496 | 7.5 HIGH | Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection |
| CVE-2026-44486 | 7.5 HIGH | Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to d |
| CVE-2026-44495 | 7.0 HIGH | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Me |
| CVE-2026-44490 | 4.8 MEDIUM | Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge fun |
| CVE-2026-44489 | 3.7 LOW | Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prot |
| CVE-2026-44487 | Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect |
No comments yet