{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-44487: Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-44487","status":"final","version":"1","initial_release_date":"2026-06-11T15:38:25.150Z","current_release_date":"2026-06-11T18:17:31.939Z","revision_history":[{"date":"2026-06-11T15:38:25.150Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy. This vulnerability is fixed in 0.32.0 and 1.16.0.","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-44487 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-44487"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-44487"},{"category":"external","summary":"https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v","url":"https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v"}]},"product_tree":{"branches":[{"category":"vendor","name":"axios","branches":[{"category":"product_name","name":"axios","branches":[{"category":"product_version","name":">= 1.0.0, < 1.16.0","product":{"name":"axios axios >= 1.0.0, < 1.16.0","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:axios:axios:*:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"< 0.32.0","product":{"name":"axios axios < 0.32.0","product_id":"CSAFPID-2","product_identification_helper":{"cpe":"cpe:2.3:a:axios:axios:*:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-44487","title":"Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter","notes":[{"category":"description","text":"Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy. This vulnerability is fixed in 0.32.0 and 1.16.0.","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1","CSAFPID-2"]},"scores":[{"cvss_v4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseScore":8.2,"baseSeverity":"HIGH"},"products":["CSAFPID-1","CSAFPID-2"]}],"remediations":[{"category":"none_available","details":"No fixed version is published yet. Monitor the upstream advisory.","product_ids":["CSAFPID-1","CSAFPID-2"]}]}]}