Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101900

6.9MEDIUM

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101900?

A vulnerability in the Axios HTTP client allows attackers to exploit inherited properties in FormData headers. This flaw arises from ResolveConfig improperly handling Symbol.toStringTag, append, and getHeaders properties from non-standard objects. As a result, attacker-controlled headers may be merged into fetch adapter requests, potentially altering important request behaviors such as authorization and caching. The issue impacts versions 1.12.0 through 1.20.0, and it has been resolved in version 1.20.0, urging all users to update promptly.

Affected Version(s)

axios >= 1.12.0, < 1.20.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.