Search CVE reports


Toggle filters

21 – 30 of 41278 results

Status is adjusted based on your filters.


CVE-2026-44494

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in...

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-44492

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request...

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-44490

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream dependency in the same process...

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-44489

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created by utils.merge() (e.g., config.proxy) are still constructed as plain {} with Object.prototype in their chain....

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-44488

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that...

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-44487

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect...

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-44486

Medium priority
Needs evaluation

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an...

1 affected package

node-axios

Package 20.04 LTS
node-axios Needs evaluation
Show less packages

CVE-2026-11816

Medium priority
Needs evaluation

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate...

1 affected package

keras

Package 20.04 LTS
keras Needs evaluation
Show less packages

CVE-2026-49214

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an...

1 affected package

php-guzzlehttp-psr7

Package 20.04 LTS
php-guzzlehttp-psr7 Needs evaluation
Show less packages

CVE-2026-48998

Medium priority
Needs evaluation

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server...

1 affected package

php-guzzlehttp-psr7

Package 20.04 LTS
php-guzzlehttp-psr7 Needs evaluation
Show less packages