axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget
zetlyn/cve-redhat vulnerability cve CVE-2026-42044 known 2026-04-24
https://access.redhat.com/security/cve/CVE-2026-42044
Properties
| cvss | 7.4receipt
What the source handed over{
"CVE": "CVE-2026-42044",
"CWE": "CWE-915",
"advisories": [
"RHSA-2026:26068",
"RHSA-2026:25271",
"RHSA-2026:34608",
"RHSA-2026:25273",
"RHSA-2026:33574",
"RHSA-2026:19375",
"RHSA-2026:20938",
"RHSA-2026:16535",
"RHSA-2026:36107",
"RHSA-2026:16534",
"RHSA-2026:20338",
"RHSA-2026:16542",
"RHSA-2026:19109",
"RHSA-2026:24539",
"RHSA-2026:24853",
"RHSA-2026:24536",
"RHSA-2026:26214",
"RHSA-2026:20454",
"RHSA-2026:26232",
"RHSA-2026:24471",
"RHSA-2026:23361",
"RHSA-2026:25089",
"RHSA-2026:24473",
"RHSA-2026:25041",
"RHSA-2026:50300",
"RHSA-2026:17657",
"RHSA-2026:17699",
"RHSA-2026:16532",
"RHSA-2026:20889",
"RHSA-2026:21338",
"RHSA-2026:42078",
"RHSA-2026:36882",
"RHSA-2026:41066",
"RHSA-2026:22629",
"RHSA-2026:21772",
"RHSA-2026:22465",
"RHSA-2026:21017",
"RHSA-2026:26225",
"RHSA-2026:22840"
],
"affected_packages": [
"openshift-service-mesh/kiali-rhel9:1778164042",
"network-observability/network-observability-console-plugin-rhel9:1780556069",
"quay/quay-rhel9:1783955846",
"satellite/iop-advisor-frontend-rhel9:1781181673",
"rhacm2/console-rhel9:1780600823",
"devspaces/code-rhel9:1779814592",
"multicluster-engine/console-mce-rhel9:1778383863",
"quay/quay-rhel8:1780891395",
"quay/quay-rhel9:1779922205",
"quay/quay-rhel8:1779822261",
"openshift-service-mesh/kiali-rhel9:1778164208",
"multicluster-engine/console-mce-rhel9:1778532610",
"quay/quay-rhel9:1779204086",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163785",
"axios",
"quay/quay-rhel8:1779811412",
"quay/quay-rhel8:1779811473",
"quay/quay-rhel8:1779689392",
"multicluster-engine/console-mce-rhel9:1780910888",
"container-native-virtualization/kubevirt-console-plugin-rhel9:1782917983",
"satellite/iop-host-inventory-frontend-rhel9:1780105179",
"automation-gateway-0:2.5.20260715-1.el8ap",
"rhacm2/console-rhel9:1783451729",
"automation-gateway-0:2.5.20260715-1.el9ap",
"advanced-cluster-security/rhacs-main-rhel8:1779293013",
"satellite/iop-vulnerability-frontend-rhel9:1781032495",
"rhtas/rhtas-console-ui-rhel9:1779971506",
"multicluster-engine/console-mce-rhel9:1778511348",
"openshift-service-mesh/kiali-ossmc-rhel8:1779520355",
"openshift-service-mesh/kiali-rhel9:1778163986",
"rhmtc/openshift-migration-ui-rhel8:1780590717",
"mta/mta-ui-rhel9:1785169013",
"rhdh/rhdh-hub-rhel9:1779841586",
"devspaces/dashboard-rhel9:1779341289",
"multicluster-engine/console-mce-rhel9:1780917531",
"rhdh/rhdh-hub-rhel9:1782761244",
"advanced-cluster-security/rhacs-main-rhel8:1779371594",
"discovery/discovery-ui-rhel9:1779395188",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163935",
"network-observability/network-observability-console-plugin-pf4-rhel9:1780920979",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163792",
"openshift-service-mesh/kiali-rhel8:1779520348",
"openshift-service-mesh/kiali-rhel9:1778163909",
"rhacm2/console-rhel9:1780876734"
],
"bugzilla": "2461624",
"bugzilla_description": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-04-24T17:49:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-42044.json",
"severity": "important"
} |
|---|---|
| cwe | CWE-915receipt
What the source handed over{
"CVE": "CVE-2026-42044",
"CWE": "CWE-915",
"advisories": [
"RHSA-2026:26068",
"RHSA-2026:25271",
"RHSA-2026:34608",
"RHSA-2026:25273",
"RHSA-2026:33574",
"RHSA-2026:19375",
"RHSA-2026:20938",
"RHSA-2026:16535",
"RHSA-2026:36107",
"RHSA-2026:16534",
"RHSA-2026:20338",
"RHSA-2026:16542",
"RHSA-2026:19109",
"RHSA-2026:24539",
"RHSA-2026:24853",
"RHSA-2026:24536",
"RHSA-2026:26214",
"RHSA-2026:20454",
"RHSA-2026:26232",
"RHSA-2026:24471",
"RHSA-2026:23361",
"RHSA-2026:25089",
"RHSA-2026:24473",
"RHSA-2026:25041",
"RHSA-2026:50300",
"RHSA-2026:17657",
"RHSA-2026:17699",
"RHSA-2026:16532",
"RHSA-2026:20889",
"RHSA-2026:21338",
"RHSA-2026:42078",
"RHSA-2026:36882",
"RHSA-2026:41066",
"RHSA-2026:22629",
"RHSA-2026:21772",
"RHSA-2026:22465",
"RHSA-2026:21017",
"RHSA-2026:26225",
"RHSA-2026:22840"
],
"affected_packages": [
"openshift-service-mesh/kiali-rhel9:1778164042",
"network-observability/network-observability-console-plugin-rhel9:1780556069",
"quay/quay-rhel9:1783955846",
"satellite/iop-advisor-frontend-rhel9:1781181673",
"rhacm2/console-rhel9:1780600823",
"devspaces/code-rhel9:1779814592",
"multicluster-engine/console-mce-rhel9:1778383863",
"quay/quay-rhel8:1780891395",
"quay/quay-rhel9:1779922205",
"quay/quay-rhel8:1779822261",
"openshift-service-mesh/kiali-rhel9:1778164208",
"multicluster-engine/console-mce-rhel9:1778532610",
"quay/quay-rhel9:1779204086",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163785",
"axios",
"quay/quay-rhel8:1779811412",
"quay/quay-rhel8:1779811473",
"quay/quay-rhel8:1779689392",
"multicluster-engine/console-mce-rhel9:1780910888",
"container-native-virtualization/kubevirt-console-plugin-rhel9:1782917983",
"satellite/iop-host-inventory-frontend-rhel9:1780105179",
"automation-gateway-0:2.5.20260715-1.el8ap",
"rhacm2/console-rhel9:1783451729",
"automation-gateway-0:2.5.20260715-1.el9ap",
"advanced-cluster-security/rhacs-main-rhel8:1779293013",
"satellite/iop-vulnerability-frontend-rhel9:1781032495",
"rhtas/rhtas-console-ui-rhel9:1779971506",
"multicluster-engine/console-mce-rhel9:1778511348",
"openshift-service-mesh/kiali-ossmc-rhel8:1779520355",
"openshift-service-mesh/kiali-rhel9:1778163986",
"rhmtc/openshift-migration-ui-rhel8:1780590717",
"mta/mta-ui-rhel9:1785169013",
"rhdh/rhdh-hub-rhel9:1779841586",
"devspaces/dashboard-rhel9:1779341289",
"multicluster-engine/console-mce-rhel9:1780917531",
"rhdh/rhdh-hub-rhel9:1782761244",
"advanced-cluster-security/rhacs-main-rhel8:1779371594",
"discovery/discovery-ui-rhel9:1779395188",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163935",
"network-observability/network-observability-console-plugin-pf4-rhel9:1780920979",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163792",
"openshift-service-mesh/kiali-rhel8:1779520348",
"openshift-service-mesh/kiali-rhel9:1778163909",
"rhacm2/console-rhel9:1780876734"
],
"bugzilla": "2461624",
"bugzilla_description": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-04-24T17:49:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-42044.json",
"severity": "important"
} |
| packages | openshift-service-mesh/kiali-rhel9:1778164042, network-observability/network-observability-console-plugin-rhel9:1780556069, quay/quay-rhel9:1783955846, satellite/iop-advisor-frontend-rhel9:1781181673, rhacm2/console-rhel9:1780600823, devspaces/code-rhel9:1779814592, multicluster-engine/console-mce-rhel9:1778383863, quay/quay-rhel8:1780891395, quay/quay-rhel9:1779922205, quay/quay-rhel8:1779822261, openshift-service-mesh/kiali-rhel9:1778164208, multicluster-engine/console-mce-rhel9:1778532610, quay/quay-rhel9:1779204086, openshift-service-mesh/kiali-ossmc-rhel9:1778163785, axios, quay/quay-rhel8:1779811412, quay/quay-rhel8:1779811473, quay/quay-rhel8:1779689392, multicluster-engine/console-mce-rhel9:1780910888, container-native-virtualization/kubevirt-console-plugin-rhel9:1782917983, satellite/iop-host-inventory-frontend-rhel9:1780105179, automation-gateway-0:2.5.20260715-1.el8ap, rhacm2/console-rhel9:1783451729, automation-gateway-0:2.5.20260715-1.el9ap, advanced-cluster-security/rhacs-main-rhel8:1779293013, satellite/iop-vulnerability-frontend-rhel9:1781032495, rhtas/rhtas-console-ui-rhel9:1779971506, multicluster-engine/console-mce-rhel9:1778511348, openshift-service-mesh/kiali-ossmc-rhel8:1779520355, openshift-service-mesh/kiali-rhel9:1778163986, rhmtc/openshift-migration-ui-rhel8:1780590717, mta/mta-ui-rhel9:1785169013, rhdh/rhdh-hub-rhel9:1779841586, devspaces/dashboard-rhel9:1779341289, multicluster-engine/console-mce-rhel9:1780917531, rhdh/rhdh-hub-rhel9:1782761244, advanced-cluster-security/rhacs-main-rhel8:1779371594, discovery/discovery-ui-rhel9:1779395188, openshift-service-mesh/kiali-ossmc-rhel9:1778163935, network-observability/network-observability-console-plugin-pf4-rhel9:1780920979, openshift-service-mesh/kiali-ossmc-rhel9:1778163792, openshift-service-mesh/kiali-rhel8:1779520348, openshift-service-mesh/kiali-rhel9:1778163909, rhacm2/console-rhel9:1780876734receipt
What the source handed over{
"CVE": "CVE-2026-42044",
"CWE": "CWE-915",
"advisories": [
"RHSA-2026:26068",
"RHSA-2026:25271",
"RHSA-2026:34608",
"RHSA-2026:25273",
"RHSA-2026:33574",
"RHSA-2026:19375",
"RHSA-2026:20938",
"RHSA-2026:16535",
"RHSA-2026:36107",
"RHSA-2026:16534",
"RHSA-2026:20338",
"RHSA-2026:16542",
"RHSA-2026:19109",
"RHSA-2026:24539",
"RHSA-2026:24853",
"RHSA-2026:24536",
"RHSA-2026:26214",
"RHSA-2026:20454",
"RHSA-2026:26232",
"RHSA-2026:24471",
"RHSA-2026:23361",
"RHSA-2026:25089",
"RHSA-2026:24473",
"RHSA-2026:25041",
"RHSA-2026:50300",
"RHSA-2026:17657",
"RHSA-2026:17699",
"RHSA-2026:16532",
"RHSA-2026:20889",
"RHSA-2026:21338",
"RHSA-2026:42078",
"RHSA-2026:36882",
"RHSA-2026:41066",
"RHSA-2026:22629",
"RHSA-2026:21772",
"RHSA-2026:22465",
"RHSA-2026:21017",
"RHSA-2026:26225",
"RHSA-2026:22840"
],
"affected_packages": [
"openshift-service-mesh/kiali-rhel9:1778164042",
"network-observability/network-observability-console-plugin-rhel9:1780556069",
"quay/quay-rhel9:1783955846",
"satellite/iop-advisor-frontend-rhel9:1781181673",
"rhacm2/console-rhel9:1780600823",
"devspaces/code-rhel9:1779814592",
"multicluster-engine/console-mce-rhel9:1778383863",
"quay/quay-rhel8:1780891395",
"quay/quay-rhel9:1779922205",
"quay/quay-rhel8:1779822261",
"openshift-service-mesh/kiali-rhel9:1778164208",
"multicluster-engine/console-mce-rhel9:1778532610",
"quay/quay-rhel9:1779204086",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163785",
"axios",
"quay/quay-rhel8:1779811412",
"quay/quay-rhel8:1779811473",
"quay/quay-rhel8:1779689392",
"multicluster-engine/console-mce-rhel9:1780910888",
"container-native-virtualization/kubevirt-console-plugin-rhel9:1782917983",
"satellite/iop-host-inventory-frontend-rhel9:1780105179",
"automation-gateway-0:2.5.20260715-1.el8ap",
"rhacm2/console-rhel9:1783451729",
"automation-gateway-0:2.5.20260715-1.el9ap",
"advanced-cluster-security/rhacs-main-rhel8:1779293013",
"satellite/iop-vulnerability-frontend-rhel9:1781032495",
"rhtas/rhtas-console-ui-rhel9:1779971506",
"multicluster-engine/console-mce-rhel9:1778511348",
"openshift-service-mesh/kiali-ossmc-rhel8:1779520355",
"openshift-service-mesh/kiali-rhel9:1778163986",
"rhmtc/openshift-migration-ui-rhel8:1780590717",
"mta/mta-ui-rhel9:1785169013",
"rhdh/rhdh-hub-rhel9:1779841586",
"devspaces/dashboard-rhel9:1779341289",
"multicluster-engine/console-mce-rhel9:1780917531",
"rhdh/rhdh-hub-rhel9:1782761244",
"advanced-cluster-security/rhacs-main-rhel8:1779371594",
"discovery/discovery-ui-rhel9:1779395188",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163935",
"network-observability/network-observability-console-plugin-pf4-rhel9:1780920979",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163792",
"openshift-service-mesh/kiali-rhel8:1779520348",
"openshift-service-mesh/kiali-rhel9:1778163909",
"rhacm2/console-rhel9:1780876734"
],
"bugzilla": "2461624",
"bugzilla_description": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-04-24T17:49:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-42044.json",
"severity": "important"
} |
| severity | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2026-42044",
"CWE": "CWE-915",
"advisories": [
"RHSA-2026:26068",
"RHSA-2026:25271",
"RHSA-2026:34608",
"RHSA-2026:25273",
"RHSA-2026:33574",
"RHSA-2026:19375",
"RHSA-2026:20938",
"RHSA-2026:16535",
"RHSA-2026:36107",
"RHSA-2026:16534",
"RHSA-2026:20338",
"RHSA-2026:16542",
"RHSA-2026:19109",
"RHSA-2026:24539",
"RHSA-2026:24853",
"RHSA-2026:24536",
"RHSA-2026:26214",
"RHSA-2026:20454",
"RHSA-2026:26232",
"RHSA-2026:24471",
"RHSA-2026:23361",
"RHSA-2026:25089",
"RHSA-2026:24473",
"RHSA-2026:25041",
"RHSA-2026:50300",
"RHSA-2026:17657",
"RHSA-2026:17699",
"RHSA-2026:16532",
"RHSA-2026:20889",
"RHSA-2026:21338",
"RHSA-2026:42078",
"RHSA-2026:36882",
"RHSA-2026:41066",
"RHSA-2026:22629",
"RHSA-2026:21772",
"RHSA-2026:22465",
"RHSA-2026:21017",
"RHSA-2026:26225",
"RHSA-2026:22840"
],
"affected_packages": [
"openshift-service-mesh/kiali-rhel9:1778164042",
"network-observability/network-observability-console-plugin-rhel9:1780556069",
"quay/quay-rhel9:1783955846",
"satellite/iop-advisor-frontend-rhel9:1781181673",
"rhacm2/console-rhel9:1780600823",
"devspaces/code-rhel9:1779814592",
"multicluster-engine/console-mce-rhel9:1778383863",
"quay/quay-rhel8:1780891395",
"quay/quay-rhel9:1779922205",
"quay/quay-rhel8:1779822261",
"openshift-service-mesh/kiali-rhel9:1778164208",
"multicluster-engine/console-mce-rhel9:1778532610",
"quay/quay-rhel9:1779204086",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163785",
"axios",
"quay/quay-rhel8:1779811412",
"quay/quay-rhel8:1779811473",
"quay/quay-rhel8:1779689392",
"multicluster-engine/console-mce-rhel9:1780910888",
"container-native-virtualization/kubevirt-console-plugin-rhel9:1782917983",
"satellite/iop-host-inventory-frontend-rhel9:1780105179",
"automation-gateway-0:2.5.20260715-1.el8ap",
"rhacm2/console-rhel9:1783451729",
"automation-gateway-0:2.5.20260715-1.el9ap",
"advanced-cluster-security/rhacs-main-rhel8:1779293013",
"satellite/iop-vulnerability-frontend-rhel9:1781032495",
"rhtas/rhtas-console-ui-rhel9:1779971506",
"multicluster-engine/console-mce-rhel9:1778511348",
"openshift-service-mesh/kiali-ossmc-rhel8:1779520355",
"openshift-service-mesh/kiali-rhel9:1778163986",
"rhmtc/openshift-migration-ui-rhel8:1780590717",
"mta/mta-ui-rhel9:1785169013",
"rhdh/rhdh-hub-rhel9:1779841586",
"devspaces/dashboard-rhel9:1779341289",
"multicluster-engine/console-mce-rhel9:1780917531",
"rhdh/rhdh-hub-rhel9:1782761244",
"advanced-cluster-security/rhacs-main-rhel8:1779371594",
"discovery/discovery-ui-rhel9:1779395188",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163935",
"network-observability/network-observability-console-plugin-pf4-rhel9:1780920979",
"openshift-service-mesh/kiali-ossmc-rhel9:1778163792",
"openshift-service-mesh/kiali-rhel8:1779520348",
"openshift-service-mesh/kiali-rhel9:1778163909",
"rhacm2/console-rhel9:1780876734"
],
"bugzilla": "2461624",
"bugzilla_description": "axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-04-24T17:49:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-42044.json",
"severity": "important"
} |
Text
axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget