StackRadar

CVE-2026-44494

High

Advisory

Published 29 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
159
of 17,781 indexed, latest versions
Container images
159
deployed by those charts
Fix available
1 of 1
affected package

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Carried by container images the latest versions of 159 of 17,781 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.1.3, 1.2.1, 1.2.2, 1.2.5+38 more1.16.0159
OSV records
GHSA-35jp-ww65-95wh

Charts affected

159 by stars
ChartLatestAffected imagesRadar Score
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
axios@1.13.6
1.16.0

Open the chart page →

2,028
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
axios@1.8.3
1.16.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.16.0

Open the chart page →

3,746
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
axios@1.7.4
1.16.0

Open the chart page →

2,789
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
axios@1.9.0
1.16.0

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
axios@1.12.2
1.16.0

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
axios@1.15.2
1.16.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.16.0

Open the chart page →

6,285
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
axios@1.3.5
1.16.0
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
axios@1.3.5
1.16.0
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
axios@1.3.5
1.16.0
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
axios@1.3.5
1.16.0

Open the chart page →

16,083

Container images carrying it

159 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flanksource/canary-checker-ui:v1.4.281764c84e550db
axios@1.6.2
1.16.0
1
fosrl/pangolin:1.13.0c32ad797ab96
axios@1.13.2
1.16.0
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
axios@1.4.0
1.16.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
axios@1.7.7
1.16.0
1
instill/console:0.68.54cd70e2df5c6
axios@1.11.0
1.16.0
1
kubevious/backend:1.2.22d9ba6eb46b6
axios@1.4.0
1.16.0
1
kubevious/collector:1.2.1f58226f9d84e
axios@1.4.0
1.16.0
1
kubevious/parser:1.2.299ae7a5168c2
axios@1.4.0
1.16.0
1
kubevious/workload-operator:1.0.20b0f4c507eb6
axios@1.3.4
1.16.0
1
kyleslugg/klusterview:latestba8c36dfdfbd
axios@1.4.0
1.16.0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
axios@1.7.7
1.16.0
1
library/ghost:6.25.12654b1e90413
axios@1.13.2
1.16.0
1
library/ghost:5.79.083f7bf209844
axios@1.6.5
1.16.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
axios@1.13.2
1.16.0
1
library/kibana:7.17.150172f1c538e7
axios@1.6.0
1.16.0
1
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.16.0
1
linuxserver/overseerr:1.35.06108ed066d4a
axios@1.3.4
1.16.0
1
litlyx/litlyx-consumer:latest02225e77d316
axios@1.13.2
1.16.0
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
axios@1.2.1
1.16.0
1
luligu/matterbridge:3.0.28f97884bebc2
axios@1.9.0
1.16.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
axios@1.3.2
1.16.0
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
axios@1.10.0
1.16.0
1
mishtinetwork/operator:latestbb3fe67a5f7c
axios@1.7.2
1.16.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
axios@1.5.0
1.16.0
1
moreillon/api-proxy:latestd7d4a5463525
axios@1.7.8
1.16.0
1
moreillon/camera-proxy:latestce60056b50c2
axios@1.7.7
1.16.0
1
moreillon/food-manager:lateste8fd856e593d
axios@1.7.7
1.16.0
1
moreillon/group-manager:latest3caa8f710ee0
axios@1.15.0
1.16.0
1
n8nio/n8n:1.86.08b39ed5a2de9
axios@1.8.2
1.16.0
1
n8nio/n8n:0.212.0a9195bc499a3
axios@1.1.3
1.16.0
1
n8nio/n8n:1.33.1dd171d45102a
axios@1.6.7
1.16.0
1
neoskop/papergirl:3.2.67f52b5949f03
axios@1.6.6
1.16.0
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
axios@1.5.1
1.16.0
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
axios@1.5.1
1.16.0
1
nocodb/nocodb:0.258.06779a4ddedf2
axios@1.7.7
1.16.0
1
nocodb/nocodb:0.301.5d9516f0bf546
axios@1.13.6
1.16.0
1
nodered/node-red:4.1.2216e7403aab9
axios@1.12.2
1.16.0
1
nodered/node-red:3.0.2-18e2632a7a35dd
axios@1.6.5
1.16.0
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
axios@1.13.6
1.16.0
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
axios@1.2.6
1.16.0
1
outlinewiki/outline:0.82.0494dfb9249a6
axios@1.7.9
1.16.0
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
axios@1.13.2
1.16.0
1
qxip/qryn:3.2.3977acc9c7a9fd
axios@1.7.7
1.16.0
1
redis/redisinsight:2.68019fcf774631
axios@1.7.7
1.16.0
1
redis/redisinsight:3.2.055542a762210
axios@1.12.2
1.16.0
1
redis/redisinsight:2.46699d341bd329
axios@1.6.7
1.16.0
1
redis/redisinsight:3.485562d67a912
axios@1.15.0
1.16.0
1
rocketadmin/rocketadmin:1.17.710955ef540b9
axios@1.15.1
1.16.0
1
sharanalwar/redchef-frontend:latest5e82950b16b7
axios@1.8.4
1.16.0
1
shyamkrishna21/shopsync:latest3998b83def53
axios@1.13.5
1.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.