Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101902
What is CVE-2026-101902?
Axios, a widely-used promise-based HTTP client for both the browser and Node.js, has a vulnerability related to prototype pollution. This issue arises when requests are made without an explicit method, allowing for the potential modification of the inherited method from Object.prototype. This can lead to unintentional submissions of state-changing HTTP requests when another vulnerability has compromised Object.prototype.method. Importantly, Axios does not create the source of this prototype pollution itself; this is a read-side gadget within the Axios request dispatch system. The vulnerability has been patched in versions 0.34.0 and 1.20.0. Users of affected versions should upgrade to these newer versions to mitigate potential security risks.
Affected Version(s)
axios >= 1.0.0, < 1.20.0 < 1.0.0, 1.20.0
axios >= 0.27.2, < 0.34.0 < 0.27.2, 0.34.0
