THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-44488 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments wh

[NVD] CVE-2026-44488 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments wh

lownvdPublished 2026-06-11

CVE-2026-44488 CVSS: 7.5 HIGH Published: 2026-06-11T17:16:32.750

Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44488