Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101902

6.9MEDIUM

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101902?

Axios, a widely-used promise-based HTTP client for both the browser and Node.js, has a vulnerability related to prototype pollution. This issue arises when requests are made without an explicit method, allowing for the potential modification of the inherited method from Object.prototype. This can lead to unintentional submissions of state-changing HTTP requests when another vulnerability has compromised Object.prototype.method. Importantly, Axios does not create the source of this prototype pollution itself; this is a read-side gadget within the Axios request dispatch system. The vulnerability has been patched in versions 0.34.0 and 1.20.0. Users of affected versions should upgrade to these newer versions to mitigate potential security risks.

Affected Version(s)

axios >= 1.0.0, < 1.20.0 < 1.0.0, 1.20.0

axios >= 0.27.2, < 0.34.0 < 0.27.2, 0.34.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.