THREAT OPS › Threat News › [NVD] CVE-2026-44488 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments wh
[NVD] CVE-2026-44488 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments wh
CVE-2026-44488 CVSS: 7.5 HIGH Published: 2026-06-11T17:16:32.750
Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive
Indicators of compromise
- CVE-2026-44488cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44488