RHSA-2026:74872

Vulnerability from csaf_redhat - Published: 2026-10-02 10:28 - Updated: 2026-10-02 22:10
Summary
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Severity
Important
Notes
Topic: An update for Red Hat Hardened Images RPMs is now available.
Details: This update includes the following RPMs: grafana13.2: * grafana13.2-13.2.1-0.9.hum1 (aarch64, x86_64) * grafana13.2-13.2.1-0.9.hum1.src (src) Security Fix(es): grafana13.2: * CVE-2026-101903
Terms of Use: This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

A flaw was found in axios. When processing HTTP/2 requests, the client fails to enforce configured proxy settings and custom Domain Name System (DNS) resolution policies. A remote attacker who can influence destination URLs could exploit this vulnerability to bypass outbound network restrictions, potentially leading to Server-Side Request Forgery (SSRF). This may allow unauthorized communication with internal network services or cloud metadata endpoints that should otherwise be blocked.

CWE-918 - Server-Side Request Forgery (SSRF)
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64 —
Vendor Fix fix
Threats
Impact Moderate

A flaw was found in Axios. This vulnerability allows an attacker to manipulate outbound network traffic by injecting arbitrary HTTP (Hypertext Transfer Protocol) headers. In environments where an attacker can exploit a separate prototype pollution flaw to modify shared object properties, the Axios fetch adapter improperly processes inherited configuration methods on request data. Consequently, an attacker can tamper with outgoing requests, potentially bypassing security controls, altering authentication tokens, or modifying backend service behavior.

CWE-1287 - Improper Validation of Specified Type of Input
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Moderate

A flaw was found in Axios. A remote attacker or an unresponsive endpoint can cause a Denial of Service (DoS) by triggering an error during HTTP/2 session initialization or reuse. Because the underlying session fails to register proper error handlers, network or session failures result in an uncaught exception that abruptly terminates the application process.

CWE-248 - Uncaught Exception
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Important

A flaw was found in axios. When sending HTTP requests that omit an explicit request method, Axios can inherit properties from the JavaScript prototype chain rather than using safe internal defaults. If an attacker manipulates shared object properties through a separate vulnerability in the same application, they can exploit this behavior to override the intended request method. This allows an attacker to force expected read-only requests to be sent as state-changing methods such as POST or DELETE, potentially resulting in unauthorized data modification or deletion.

CWE-454 - External Initialization of Trusted Variables or Data Stores
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Moderate

A flaw was found in Axios. A remote attacker can exploit this vulnerability by supplying a crafted data URL containing repeated slash characters to an application that processes untrusted inputs. Due to an inefficient regular expression used to parse the URL, handling the malformed input triggers excessive backtracking that blocks the main execution thread. This freezes application processing and causes a Denial of Service (DoS).

CWE-1333 - Inefficient Regular Expression Complexity
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Important

A flaw was found in Axios. If a separate vulnerability modifies shared object properties (prototype pollution) in the application environment, Axios may inherit those properties when processing request configurations rebuilt without explicit headers. An attacker can exploit this condition to inject unauthorized HTTP headers into outgoing network requests. This issue can lead to improper request routing, access control bypasses, or downstream cache poisoning.

CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Moderate

A flaw was found in axios. When running in Node.js, the HTTP adapter does not define an explicit connection creation setting on outgoing request options. If a separate prototype-pollution flaw is exploited in the same process, an attacker can hijack the network socket by injecting a malicious connection handler. This allows the attacker to redirect outbound requests to an attacker-controlled server, resulting in information disclosure of sensitive credentials and the ability to return forged responses.

CWE-941 - Incorrectly Specified Destination in a Communication Channel
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Important

A flaw was found in axios. A remote attacker operating a malicious server can cause a Denial of Service (DoS) by returning an HTTP redirect containing a crafted hostname. When proxy bypass settings are configured, the application processes the hostname with an inefficient regular expression that consumes excessive computational time. This processing blocks the application's execution thread, leaving the service unresponsive to other requests.

CWE-1333 - Inefficient Regular Expression Complexity
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Important

A flaw was found in Axios. When configured to use the fetch adapter, the application does not enforce settings configured to disable HTTP redirects. A remote attacker controlling a redirecting server can exploit this behavior to force the application to follow redirects to internal endpoints, resulting in Server-Side Request Forgery (SSRF). This flaw can allow attackers to access internal services and expose sensitive data or trigger state-changing actions on internal systems.

CWE-918 - Server-Side Request Forgery (SSRF)
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Moderate

A flaw was found in Axios. When using the fetch adapter, Axios fails to properly isolate request configuration options from inherited object properties. If an attacker first exploits a separate prototype pollution vulnerability (where shared JavaScript object properties are modified) within the application, the fetch adapter can inherit those manipulated headers into outbound network calls. This allows an attacker to alter outgoing requests, potentially bypassing authorization controls, corrupting cache behavior, or accessing restricted internal services.

CWE-628 - Function Call with Incorrectly Specified Arguments
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Moderate

A flaw was found in axios. In applications affected by prototype pollution, where an attacker can modify base JavaScript object properties, axios processes inherited options during form data serialization without verifying property ownership. An attacker can leverage this behavior to trigger a Denial of Service (DoS) by causing requests to fail, alter outgoing serialized request data, or potentially execute arbitrary code if function injection is possible.

CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes
Affected products
Fixed 3 products, the same list as for CVE-2026-101898
Threats
Impact Important
References
URL Category
https://access.redhat.com/errata/RHSA-2026:74872 self
https://access.redhat.com/security/cve/CVE-2026-101903 external
https://access.redhat.com/security/updates/classi… external
https://images.redhat.com/ external
https://access.redhat.com/security/cve/CVE-2026-101905 external
https://access.redhat.com/security/cve/CVE-2026-101902 external
https://access.redhat.com/security/cve/CVE-2026-101901 external
https://access.redhat.com/security/cve/CVE-2026-101904 external
https://access.redhat.com/security/cve/CVE-2026-101906 external
https://access.redhat.com/security/cve/CVE-2026-101898 external
https://access.redhat.com/security/cve/CVE-2026-101907 external
https://access.redhat.com/security/cve/CVE-2026-101908 external
https://access.redhat.com/security/cve/CVE-2026-101909 external
https://access.redhat.com/security/cve/CVE-2026-101900 external
https://security.access.redhat.com/data/csaf/v2/a… self
https://access.redhat.com/security/cve/CVE-2026-101898 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542571 external
https://www.cve.org/CVERecord?id=CVE-2026-101898 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101898 external
https://github.com/axios/axios/commit/d19040bda7a… external
https://github.com/axios/axios/pull/11141 external
https://github.com/axios/axios/releases/tag/v1.20.0 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101900 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542576 external
https://www.cve.org/CVERecord?id=CVE-2026-101900 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101900 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101901 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542577 external
https://www.cve.org/CVERecord?id=CVE-2026-101901 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101901 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101902 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542575 external
https://www.cve.org/CVERecord?id=CVE-2026-101902 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101902 external
https://github.com/axios/axios/releases/tag/v0.34.0 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101903 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542580 external
https://www.cve.org/CVERecord?id=CVE-2026-101903 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101903 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101904 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542579 external
https://www.cve.org/CVERecord?id=CVE-2026-101904 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101904 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101905 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542584 external
https://www.cve.org/CVERecord?id=CVE-2026-101905 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101905 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101906 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542583 external
https://www.cve.org/CVERecord?id=CVE-2026-101906 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101906 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101907 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542586 external
https://www.cve.org/CVERecord?id=CVE-2026-101907 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101907 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101908 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542592 external
https://www.cve.org/CVERecord?id=CVE-2026-101908 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101908 external
https://github.com/axios/axios/security/advisorie… external
https://access.redhat.com/security/cve/CVE-2026-101909 self
https://bugzilla.redhat.com/show_bug.cgi?id=2542593 external
https://www.cve.org/CVERecord?id=CVE-2026-101909 external
https://nvd.nist.gov/vuln/detail/CVE-2026-101909 external
https://github.com/axios/axios/commit/d29be181f85… external
https://github.com/axios/axios/security/advisorie… external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "An update for Red Hat Hardened Images RPMs is now available.",
        "title": "Topic"
      },
      {
        "category": "general",
        "text": "This update includes the following RPMs:\n\ngrafana13.2:\n  * grafana13.2-13.2.1-0.9.hum1 (aarch64, x86_64)\n  * grafana13.2-13.2.1-0.9.hum1.src (src)\n\nSecurity Fix(es):\n\ngrafana13.2:\n  * CVE-2026-101903",
        "title": "Details"
      },
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://access.redhat.com/errata/RHSA-2026:74872",
        "url": "https://access.redhat.com/errata/RHSA-2026:74872"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101903",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101903"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/updates/classification/",
        "url": "https://access.redhat.com/security/updates/classification/"
      },
      {
        "category": "external",
        "summary": "https://images.redhat.com/",
        "url": "https://images.redhat.com/"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101905",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101905"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101902",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101902"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101901",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101901"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101904",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101904"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101906",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101906"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101898",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101898"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101907",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101907"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101908",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101908"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101909",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101909"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-101900",
        "url": "https://access.redhat.com/security/cve/CVE-2026-101900"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74872.json"
      }
    ],
    "title": "Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update",
    "tracking": {
      "current_release_date": "2026-10-02T22:10:04+00:00",
      "generator": {
        "date": "2026-10-02T22:10:04+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.4.0"
        }
      },
      "id": "RHSA-2026:74872",
      "initial_release_date": "2026-10-02T10:28:50+00:00",
      "revision_history": [
        {
          "date": "2026-10-02T10:28:50+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-10-02T18:12:52+00:00",
          "number": "2",
          "summary": "Last updated version"
        },
        {
          "date": "2026-10-02T22:10:04+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Hardened Images",
                "product": {
                  "name": "Red Hat Hardened Images",
                  "product_id": "Red Hat Hardened Images",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:hummingbird:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Hardened Images"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "grafana13.2-0:13.2.1-0.9.hum1@aarch64",
                "product": {
                  "name": "grafana13.2-0:13.2.1-0.9.hum1@aarch64",
                  "product_id": "grafana13.2-0:13.2.1-0.9.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/grafana13.2@13.2.1-0.9.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "grafana13.2-0:13.2.1-0.9.hum1@src",
                "product": {
                  "name": "grafana13.2-0:13.2.1-0.9.hum1@src",
                  "product_id": "grafana13.2-0:13.2.1-0.9.hum1@src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/grafana13.2@13.2.1-0.9.hum1?arch=src\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-source-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "grafana13.2-0:13.2.1-0.9.hum1@x86_64",
                "product": {
                  "name": "grafana13.2-0:13.2.1-0.9.hum1@x86_64",
                  "product_id": "grafana13.2-0:13.2.1-0.9.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/grafana13.2@13.2.1-0.9.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana13.2-0:13.2.1-0.9.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64"
        },
        "product_reference": "grafana13.2-0:13.2.1-0.9.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana13.2-0:13.2.1-0.9.hum1@src as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src"
        },
        "product_reference": "grafana13.2-0:13.2.1-0.9.hum1@src",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "grafana13.2-0:13.2.1-0.9.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        },
        "product_reference": "grafana13.2-0:13.2.1-0.9.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-101898",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "discovery_date": "2026-09-28T17:30:59.220196+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542571"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in axios. When processing HTTP/2 requests, the client fails to enforce configured proxy settings and custom Domain Name System (DNS) resolution policies. A remote attacker who can influence destination URLs could exploit this vulnerability to bypass outbound network restrictions, potentially leading to Server-Side Request Forgery (SSRF). This may allow unauthorized communication with internal network services or cloud metadata endpoints that should otherwise be blocked.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: axios: Security control bypass via unapplied HTTP/2 proxy and DNS settings",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101898"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542571",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542571"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101898",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101898"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101898",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101898"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-3pq3-5fj3-cg6v"
        }
      ],
      "release_date": "2026-09-28T17:10:16.044000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "axios: axios: Security control bypass via unapplied HTTP/2 proxy and DNS settings"
    },
    {
      "cve": "CVE-2026-101900",
      "cwe": {
        "id": "CWE-1287",
        "name": "Improper Validation of Specified Type of Input"
      },
      "discovery_date": "2026-09-28T17:31:17.948326+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542576"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Axios. This vulnerability allows an attacker to manipulate outbound network traffic by injecting arbitrary HTTP (Hypertext Transfer Protocol) headers. In environments where an attacker can exploit a separate prototype pollution flaw to modify shared object properties, the Axios fetch adapter improperly processes inherited configuration methods on request data. Consequently, an attacker can tamper with outgoing requests, potentially bypassing security controls, altering authentication tokens, or modifying backend service behavior.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: Axios: Outbound HTTP header injection via prototype pollution in fetch adapter",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101900"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542576",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542576"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101900",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101900"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101900",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101900"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2"
        }
      ],
      "release_date": "2026-09-28T17:14:07.108000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "axios: Axios: Outbound HTTP header injection via prototype pollution in fetch adapter"
    },
    {
      "cve": "CVE-2026-101901",
      "cwe": {
        "id": "CWE-248",
        "name": "Uncaught Exception"
      },
      "discovery_date": "2026-09-28T17:32:31.437233+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542577"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Axios. A remote attacker or an unresponsive endpoint can cause a Denial of Service (DoS) by triggering an error during HTTP/2 session initialization or reuse. Because the underlying session fails to register proper error handlers, network or session failures result in an uncaught exception that abruptly terminates the application process.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: Axios: Denial of Service via unhandled error in HTTP/2 session initialization",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101901"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542577",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542577"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101901",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101901"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101901",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101901"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-542g-h47m-68v8"
        }
      ],
      "release_date": "2026-09-28T17:16:21.868000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "axios: Axios: Denial of Service via unhandled error in HTTP/2 session initialization"
    },
    {
      "cve": "CVE-2026-101902",
      "cwe": {
        "id": "CWE-454",
        "name": "External Initialization of Trusted Variables or Data Stores"
      },
      "discovery_date": "2026-09-28T17:31:32.389933+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542575"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in axios. When sending HTTP requests that omit an explicit request method, Axios can inherit properties from the JavaScript prototype chain rather than using safe internal defaults. If an attacker manipulates shared object properties through a separate vulnerability in the same application, they can exploit this behavior to override the intended request method. This allows an attacker to force expected read-only requests to be sent as state-changing methods such as POST or DELETE, potentially resulting in unauthorized data modification or deletion.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: axios: Unintended HTTP method override via prototype pollution gadget",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101902"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542575",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542575"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101902",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101902"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101902",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101902"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v0.34.0",
          "url": "https://github.com/axios/axios/releases/tag/v0.34.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g"
        }
      ],
      "release_date": "2026-09-28T17:22:49.113000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "axios: axios: Unintended HTTP method override via prototype pollution gadget"
    },
    {
      "cve": "CVE-2026-101903",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "discovery_date": "2026-09-28T17:41:27.330001+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542580"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Axios. A remote attacker can exploit this vulnerability by supplying a crafted data URL containing repeated slash characters to an application that processes untrusted inputs. Due to an inefficient regular expression used to parse the URL, handling the malformed input triggers excessive backtracking that blocks the main execution thread. This freezes application processing and causes a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: Axios: Denial of Service via malformed data URLs",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101903"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542580",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542580"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101903",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101903"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101903",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101903"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-c29m-xwm3-cm6r"
        }
      ],
      "release_date": "2026-09-28T17:25:04.448000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "axios: Axios: Denial of Service via malformed data URLs"
    },
    {
      "cve": "CVE-2026-101904",
      "cwe": {
        "id": "CWE-915",
        "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes"
      },
      "discovery_date": "2026-09-28T17:41:01.533146+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542579"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Axios. If a separate vulnerability modifies shared object properties (prototype pollution) in the application environment, Axios may inherit those properties when processing request configurations rebuilt without explicit headers. An attacker can exploit this condition to inject unauthorized HTTP headers into outgoing network requests. This issue can lead to improper request routing, access control bypasses, or downstream cache poisoning.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: Axios: HTTP header injection via inherited prototype properties",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101904"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542579",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542579"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101904",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101904"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101904",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101904"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-j8rh-479h-cp32"
        }
      ],
      "release_date": "2026-09-28T17:29:10.996000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "axios: Axios: HTTP header injection via inherited prototype properties"
    },
    {
      "cve": "CVE-2026-101905",
      "cwe": {
        "id": "CWE-941",
        "name": "Incorrectly Specified Destination in a Communication Channel"
      },
      "discovery_date": "2026-09-28T17:42:49.229695+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542584"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in axios. When running in Node.js, the HTTP adapter does not define an explicit connection creation setting on outgoing request options. If a separate prototype-pollution flaw is exploited in the same process, an attacker can hijack the network socket by injecting a malicious connection handler. This allows the attacker to redirect outbound requests to an attacker-controlled server, resulting in information disclosure of sensitive credentials and the ability to return forged responses.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: axios: Request socket hijacking via inherited createConnection property",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101905"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542584",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542584"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101905",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101905"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101905",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101905"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3"
        }
      ],
      "release_date": "2026-09-28T17:31:00.916000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "axios: axios: Request socket hijacking via inherited createConnection property"
    },
    {
      "cve": "CVE-2026-101906",
      "cwe": {
        "id": "CWE-1333",
        "name": "Inefficient Regular Expression Complexity"
      },
      "discovery_date": "2026-09-28T17:42:29.749788+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542583"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in axios. A remote attacker operating a malicious server can cause a Denial of Service (DoS) by returning an HTTP redirect containing a crafted hostname. When proxy bypass settings are configured, the application processes the hostname with an inefficient regular expression that consumes excessive computational time. This processing blocks the application\u0027s execution thread, leaving the service unresponsive to other requests.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: axios: Denial of Service via crafted redirect hostname",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101906"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542583",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542583"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101906",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101906"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101906",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101906"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj"
        }
      ],
      "release_date": "2026-09-28T17:32:40.772000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "axios: axios: Denial of Service via crafted redirect hostname"
    },
    {
      "cve": "CVE-2026-101907",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "discovery_date": "2026-09-28T17:51:24.121931+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542586"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Axios. When configured to use the fetch adapter, the application does not enforce settings configured to disable HTTP redirects. A remote attacker controlling a redirecting server can exploit this behavior to force the application to follow redirects to internal endpoints, resulting in Server-Side Request Forgery (SSRF). This flaw can allow attackers to access internal services and expose sensitive data or trigger state-changing actions on internal systems.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: Axios: Server-Side Request Forgery via bypassed redirect restrictions in fetch adapter",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101907"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542586",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542586"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101907",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101907"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101907",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101907"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-r4gj-5m52-g5wh"
        }
      ],
      "release_date": "2026-09-28T17:36:03.648000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "axios: Axios: Server-Side Request Forgery via bypassed redirect restrictions in fetch adapter"
    },
    {
      "cve": "CVE-2026-101908",
      "cwe": {
        "id": "CWE-628",
        "name": "Function Call with Incorrectly Specified Arguments"
      },
      "discovery_date": "2026-09-28T17:53:21.539962+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542592"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Axios. When using the fetch adapter, Axios fails to properly isolate request configuration options from inherited object properties. If an attacker first exploits a separate prototype pollution vulnerability (where shared JavaScript object properties are modified) within the application, the fetch adapter can inherit those manipulated headers into outbound network calls. This allows an attacker to alter outgoing requests, potentially bypassing authorization controls, corrupting cache behavior, or accessing restricted internal services.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: Axios: Outbound HTTP request manipulation via fetch adapter prototype pollution",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101908"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542592",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542592"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101908",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101908"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101908",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101908"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8"
        }
      ],
      "release_date": "2026-09-28T17:38:55.303000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "axios: Axios: Outbound HTTP request manipulation via fetch adapter prototype pollution"
    },
    {
      "cve": "CVE-2026-101909",
      "cwe": {
        "id": "CWE-915",
        "name": "Improperly Controlled Modification of Dynamically-Determined Object Attributes"
      },
      "discovery_date": "2026-09-28T17:53:39.519728+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2542593"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in axios. In applications affected by prototype pollution, where an attacker can modify base JavaScript object properties, axios processes inherited options during form data serialization without verifying property ownership. An attacker can leverage this behavior to trigger a Denial of Service (DoS) by causing requests to fail, alter outgoing serialized request data, or potentially execute arbitrary code if function injection is possible.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "axios: axios: Denial of Service via prototype pollution gadget in form serialization",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
          "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-101909"
        },
        {
          "category": "external",
          "summary": "RHBZ#2542593",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2542593"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-101909",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-101909"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-101909",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101909"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a",
          "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b",
          "url": "https://github.com/axios/axios/commit/d29be181f85f6fe93397a07b1f69606d9622637b"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/pull/11141",
          "url": "https://github.com/axios/axios/pull/11141"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v0.34.0",
          "url": "https://github.com/axios/axios/releases/tag/v0.34.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/releases/tag/v1.20.0",
          "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f",
          "url": "https://github.com/axios/axios/security/advisories/GHSA-x97p-jq2g-jp4f"
        }
      ],
      "release_date": "2026-09-28T17:42:40.203000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-10-02T10:28:50+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74872"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@aarch64",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@src",
            "Red Hat Hardened Images:grafana13.2-0:13.2.1-0.9.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "axios: axios: Denial of Service via prototype pollution gadget in form serialization"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…