[Git][security-tracker-team/security-tracker][master] new node-axios issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Jun 12 12:17:19 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
08ae30c4 by Moritz Muehlenhoff at 2026-06-12T13:17:07+02:00
new node-axios issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -495,23 +495,35 @@ CVE-2026-44693 (Pi-hole FTL is the core engine of the Pi-hole network-level adve
 CVE-2026-44692 (Sharp is a content management framework built for Laravel as a package ...)
 	TODO: check
 CVE-2026-44496 (Axios is a promise based HTTP client for the browser and Node.js. Axio ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf
 CVE-2026-44495 (Axios is a promise based HTTP client for the browser and Node.js. From ...)
-	TODO: check
+	- node-axios 1.15.2-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw
 CVE-2026-44494 (Axios is a promise based HTTP client for the browser and Node.js. From ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-35jp-ww65-95wh
 CVE-2026-44492 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv
 CVE-2026-44490 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-898c-q2cr-xwhg
 CVE-2026-44489 (Axios is a promise based HTTP client for the browser and Node.js. From ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	[trixie] - node-axios <not-affected> (Vulnerable code not present, introduced in 1.15.2)
+	[bookworm] - node-axios <not-affected> (Vulnerable code not present, introduced in 1.15.2)
+	[bullseye] - node-axios <not-affected> (Vulnerable code not present, introduced in 1.15.2)
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-654m-c8p4-x5fp
 CVE-2026-44488 (Axios is a promise based HTTP client for the browser and Node.js. Axio ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf
 CVE-2026-44487 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v
 CVE-2026-44486 (Axios is a promise based HTTP client for the browser and Node.js. Prio ...)
-	TODO: check
+	- node-axios 1.16.0-1
+	NOTE: https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc
 CVE-2026-42568 (Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.1 ...)
 	NOT-FOR-US: Yamcs
 CVE-2026-42558 (Xibo is an open source digital signage platform with a web content man ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08ae30c4b04bb3a35acaff935a515ea697654089

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/08ae30c4b04bb3a35acaff935a515ea697654089
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260612/da65e5c4/attachment.htm>


More information about the debian-security-tracker-commits mailing list