Axios vulnerability under CVE-2026-44494 #22406
Closed
mcgraw-syrx
started this conversation in
General
Replies: 2 comments
|
Thanks for reporting this. Axios is included as a dependency of the MSSQL extension, and version 1.43.0 contains Axios 1.15.2, which is affected by CVE-2026-44494. We upgraded Axios to the patched version 1.16.0 in #22247. This fix is included in MSSQL extension 1.44.0, released July 15. Please upgrade to version 1.44.0 or later. If Defender continues reporting the vulnerability afterward, check for a retained installation directory for extension version 1.43.0 and remove it. |
0 replies
|
Aasim,
Good morning! Thank you for the wonderful news. Our security team will be very happy that this vulnerability has been patched. We'll review all our deployments and be sure everyone has applied the extension updates!
Mike McGraw
IT Director – Business Systems
414-410-8134 Office
ServeYouRx.com<https://serveyourx.com/> | LinkedIn<https://www.linkedin.com/company/serve-you-custom-rx-management>
…________________________________
From: Aasim Khan ***@***.***>
Sent: Saturday, August 1, 2026 5:36 PM
To: microsoft/vscode-mssql ***@***.***>
Cc: Mike McGraw ***@***.***>; Author ***@***.***>
Subject: [External] Re: [microsoft/vscode-mssql] Axios vulnerability under CVE-2026-44494 (Discussion #22406)
You don't often get email from ***@***.*** Learn why this is important<https://aka.ms/LearnAboutSenderIdentification>
CAUTION: This email was sent from an EXTERNAL source. Use caution when clicking links or opening attachments.
Thanks for reporting this. Axios is included as a dependency of the MSSQL extension, and version 1.43.0 contains Axios 1.15.2, which is affected by CVE-2026-44494<https://github.com/advisories/GHSA-35jp-ww65-95wh>.
We upgraded Axios to the patched version 1.16.0 in #22247<#22247>. This fix is included in MSSQL extension 1.44.0, released July 15. Please upgrade to version 1.44.0 or later.
If Defender continues reporting the vulnerability afterward, check for a retained installation directory for extension version 1.43.0 and remove it.
—
Reply to this email directly, view it on GitHub<#22406?email_source=notifications&email_token=BOZAKTY6DNRV4TLF2T5VQDL5HZWIRA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZYGY3DGNBYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVRTG633UMVZF6Y3MNFRWW#discussioncomment-17866348>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/BOZAKT2D64KLQO7FLMLCTYL5HZWIRAVCNFSNUABHKJSXA33TNF2G64TZHM3DCOJXGM4DKMZ3IRUXGY3VONZWS33OHMYTAMZUG42TIMFBOYBA>.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS<https://github.com/notifications/mobile/ios/BOZAKT2BRFFAHZIKY5DJMDL5HZWIRA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZYGY3DGNBYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVJTG633UMVZF62LPOM> and Android<https://github.com/notifications/mobile/android/BOZAKT4GZ6I476L64MZEJL35HZWIRA5CNFSNUABIM5UWIORPF5TWS5BNNB2WEL2ENFZWG5LTONUW63SDN5WW2ZLOOQXTCNZYGY3DGNBYUZZGKYLTN5XKMYLVORUG64VFMV3GK3TUVZTG633UMVZF6YLOMRZG62LE>. Download it today!
You are receiving this because you authored the thread.Message ID: ***@***.***>
The information contained in this communication may be confidential, is intended only for the use of the recipient(s) sent to, and may be legally privileged. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this communication, or any of its contents, is strictly prohibited. If you have received this communication in error, please notify the sender immediately and destroy the original message. If you have any questions concerning this message, please contact the sender.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
My latest Microsoft Defender vulnerability report just began including an application called Axios. I investigated and learned that it's a JavaScript library for HTTP connections. The vulnerability flags this mssql extension for VS Code as having this library and this vulnerability. I have the latest 1.43.0 release of this extension.
Can anyone confirm my hypothesis that Axios is embedded in this extension? If so, is there a path to patching this vulnerability?
All reactions