Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101900
6.9MEDIUM
What is CVE-2026-101900?
A vulnerability in the Axios HTTP client allows attackers to exploit inherited properties in FormData headers. This flaw arises from ResolveConfig improperly handling Symbol.toStringTag, append, and getHeaders properties from non-standard objects. As a result, attacker-controlled headers may be merged into fetch adapter requests, potentially altering important request behaviors such as authorization and caching. The issue impacts versions 1.12.0 through 1.20.0, and it has been resolved in version 1.20.0, urging all users to update promptly.
Affected Version(s)
axios >= 1.12.0, < 1.20.0
