Junglewise Threat Intelligence

CVE-2026-44487: Axios Proxy-Authorization credential leak in Node.js HTTP adapter

CVE-2026-44487 · Severity: high · CVSS 4 · Published 2026-06-11

Technologies: Axios. Vendors: Axios.

Executive brief

Axios is a popular library used by developers to make web requests in Node.js applications. A security flaw in its Node.js component can cause sensitive proxy login credentials to be accidentally sent to an external website during a page redirect. If an attacker controls the destination website, they could steal these credentials and potentially gain unauthorized access to the organization's internal web proxy.

Technical details

A credential leak exists in the Axios Node.js HTTP adapter's handling of redirects. When an initial request is made through an authenticated HTTP proxy and subsequently redirects to a URL that does not require a proxy (e.g., due to NO_PROXY settings or missing HTTPS_PROXY configuration), the 'setProxy()' function in 'lib/adapters/http.js' fails to clear the 'Proxy-Authorization' header inherited from the initial request. If the redirect layer does not strip the header (often occurring in same-host redirect shapes), the sensitive proxy credentials are sent to the final origin. This vulnerability is specific to the Node.js environment and does not affect browser-based usage. The issue is resolved in versions 0.32.0 and 1.16.0 by ensuring the header is explicitly removed during redirect re-invocation.

Affected products

  • Axios Axios >=1.0.0 <1.16.0, <0.32.0

Timeline

  • 2026-05-30: advisory: GitHub Security Advisory GHSA-p92q-9vqr-4j8v published
  • 2026-06-11: disclosed: CVE-2026-44487 published to NVD

References

Related threats