CVE Intelligence
Skip to main content
HIGH

CVE-2026-44496

CVE-2026-44496 — Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.

Published Updated Sources: cvelistV5, GitHub_M

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

axios

65 products listed

CVSS base

7.5

HIGH

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

PoC

none · proof-of-concept · active

Automatable

Yes

can an attacker script all four kill-chain steps

Technical impact

Partial

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (2)

Products (65)

axiosred hat amq broker 7 13 6red hat amq broker 7 14 1red hat ansible automation platform 2 5 for rhel 8red hat ansible automation platform 2 5 for rhel 9red hat build of apicurio registry 3 3 1red hat data grid 8 6 2multicluster engine for kubernetes 2 1multicluster engine for kubernetes 2 6multicluster engine for kubernetes 2 8multicluster engine for kubernetes 2 9red hat advanced cluster management for kubernetes 2 11red hat advanced cluster management for kubernetes 2 13red hat advanced cluster management for kubernetes 2 14red hat advanced cluster management for kubernetes 2 15red hat advanced cluster management for kubernetes 2 16red hat advanced cluster security 4 9red hat advanced cluster security for kubernetes 4 10red hat ansible automation platform 2 7red hat developer hub 1 10red hat developer hub 1 9red hat discovery 2red hat migration toolkit 1 8red hat migration toolkit for applications 8 1red hat openshift ai 3 4red hat openshift container platform 4 12red hat openshift container platform 4 14red hat openshift container platform 4 15red hat openshift container platform 4 16red hat openshift container platform 4 19red hat openshift container platform 4 20red hat openshift container platform 4 21red hat openshift dev spaces 3 29red hat openshift service mesh 2 6red hat openshift service mesh 3 0red hat openshift service mesh 3 1red hat openshift service mesh 3 2red hat openshift service mesh 3 3red hat quay 3 10red hat quay 3 12red hat quay 3 15red hat quay 3 16red hat quay 3 9red hat trusted artifact signer 1 3cryostat 4gatekeeper 3migration toolkit for applications 8network observability operatoropenshift pipelinesopenshift service mesh 3red hat 3scale api management platform 2red hat ansible automation platform 2red hat build of apache camel for spring boot 4red hat build of apache camel hawtio 4red hat build of podman desktop tech previewred hat enterprise linux 8red hat enterprise linux 9red hat enterprise linux ai rhel ai 3red hat fuse 7red hat openshift ai rhoaired hat openshift container platform 4red hat openshift virtualization 4red hat satellite 6red hat trusted profile analyzerself service automation portal 2

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
7.5CVSS 3.1HIGHcvelistV5

Weakness & attack patterns

  • CWE-400
  • CWE-1333

Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.

  • T1499Endpoint Denial of Service

References

25 on the record

Elsewhere on this site

  • axiosevery CVE for this vendor
  • redhatevery CVE for this vendor
  • CWE-400other pages naming this weakness

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.