CVE-2026-44494 is a prototype pollution gadget in Axios affecting the Node.js HTTP adapter in versions 1.0.0 through before 1.16.0. The flaw arises because Axios reads the proxy configuration through normal property access on the merged request configuration object, allowing lookup to traverse the JavaScript prototype chain. Since proxy is not established as an own property in the relevant merged configuration path, attacker-controlled pollution of Object.prototype can inject a proxy configuration that Axios treats as legitimate. When the HTTP adapter processes requests, the proxy handling logic can then route outbound traffic through an attacker-controlled intermediary. This turns an otherwise separate prototype pollution condition elsewhere in the application or dependency tree into a full traffic interception primitive for Axios-based server-side HTTP communications.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A companion Axios vulnerability involving MITM risk via prototype pollution in config.proxy, mentioned because it is fixed in the same releases as CVE-2026-44492.
A prototype pollution gadget in Axios's Node.js HTTP adapter that lets polluted Object.prototype.proxy values be treated as legitimate proxy configuration, enabling attacker-controlled MITM interception and modification of Axios HTTP traffic.
An Axios vulnerability in the backend file adapter that enables escalation of Object.prototype pollution into a full man-in-the-middle attack, allowing interception and modification of outgoing HTTP requests and exposure of sensitive authentication data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.