StackRadar

CVE-2026-44494

High

Advisory

Published 29 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
159
of 17,781 indexed, latest versions
Container images
159
deployed by those charts
Fix available
1 of 1
affected package

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

Carried by container images the latest versions of 159 of 17,781 indexed charts deploy, on 159 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.1.3, 1.2.1, 1.2.2, 1.2.5+38 more1.16.0159
OSV records
GHSA-35jp-ww65-95wh

Charts affected

159 by stars
ChartLatestAffected imagesRadar Score
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
axios@1.13.6
1.16.0

Open the chart page →

2,028
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
axios@1.8.3
1.16.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.16.0

Open the chart page →

3,746
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
axios@1.7.4
1.16.0

Open the chart page →

2,789
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
axios@1.9.0
1.16.0

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
axios@1.12.2
1.16.0

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
axios@1.15.2
1.16.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.16.0

Open the chart page →

6,285
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-44494.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
axios@1.3.5
1.16.0
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
axios@1.3.5
1.16.0
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
axios@1.3.5
1.16.0
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
axios@1.3.5
1.16.0

Open the chart page →

16,083

Container images carrying it

159 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
axios@1.6.5
1.16.0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
axios@1.4.0
1.16.0
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
axios@1.15.0
1.16.0
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
axios@1.13.6
1.16.0
3
ethersphere/bee-localchain:latest0558799ca992
axios@1.6.8
1.16.0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
axios@1.7.2
1.16.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
axios@1.7.5
1.16.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
axios@1.11.0
1.16.0
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
axios@1.8.4
1.16.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
axios@1.9.0
1.16.0
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
axios@1.6.7
1.16.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
axios@1.13.0
1.16.0
2
rajnandan1/kener:3.2.1930407afca731
axios@1.8.3
1.16.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
axios@1.6.7
1.16.0
2
requarks/wiki:2:latest68f0d1848261
axios@1.15.2
1.16.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
axios@1.6.0
1.16.0
2
activepieces/activepieces:0.23.0c26188b44e62
axios@1.6.7
1.16.0
1
actualbudget/actual-server:25.3.158fecd9088b7
axios@1.7.9
1.16.0
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
axios@1.7.4
1.16.0
1
alazidis/stornx:1.1.1602d4f7f090c
axios@1.9.0
1.16.0
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
axios@1.7.7
1.16.0
1
assistiot/composite-services-manager_agent-http-mqtt:latest16d21bc5e42e
axios@1.6.8
1.16.0
1
assistiot/composite-services-manager_agent-mqtt-http:latest27d58b8911cd
axios@1.6.8
1.16.0
1
assistiot/dlt_api:2.1.0c8a170683be7
axios@1.6.5
1.16.0
1
assistiot/monitoring_notifying:2.0.068324d0fa5bb
axios@1.6.5
1.16.0
1
assistiot/multi-link_client:latestcf048365d042
axios@1.3.6
1.16.0
1
automatischio/automatisch:0.15.03bace7a12d5f
axios@1.9.0
1.16.0
1
baserow/baserow:1.30.1df0c42eb67e8
axios@1.7.7
1.16.0
1
budibase/apps:3.41.344fe6feab985
axios@1.15.2
1.16.0
1
chainsafe/lodestar:latest5593f6e97912
axios@1.13.3
1.16.0
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
axios@1.7.4
1.16.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
axios@1.3.2
1.16.0
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
axios@1.8.3
1.16.0
1
countly/api:25.05.4f4cc7447c4f5
axios@1.6.5
1.16.0
1
countly/countly-server:25.05.4e3c238248f99
axios@1.6.5
1.16.0
1
countly/frontend:25.05.42acbc11499b6
axios@1.6.5
1.16.0
1
cryptexlabs/authf:0.12.11189c07411d7c
axios@1.7.7
1.16.0
1
defactops/defactops-backend:1.0.2307b663c0092a
axios@1.2.2
1.16.0
1
directus/directus:11.1.0e3c8bb975350
axios@1.7.3
1.16.0
1
documenso/documenso:v1.8.17f16a9449f18
axios@1.6.2
1.16.0
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
axios@1.7.7
1.16.0
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
axios@1.13.2
1.16.0
1
etherpad/etherpad:2.7.2b723fe5f2594
axios@1.15.2
1.16.0
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
axios@1.2.5
1.16.0
1
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.16.0
1
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
axios@1.13.2
1.16.0
1
fallenbagel/jellyseerr:latest4538137bc5af
axios@1.10.0
1.16.0
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
axios@1.3.4
1.16.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
axios@1.5.1
1.16.0
1
fiware/idm:8.3.3a1b6ed4ae84f
axios@1.3.4
1.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.