Prototype Pollution in Axios HTTP Client Impacts Multiple Versions
CVE-2026-101904

6.9MEDIUM

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101904?

In Axios, a promise-based HTTP client, versions from 1.0.0 to 1.20.0 are susceptible to a prototype pollution issue that allows attacker-controlled headers to be resolved and exposed during request processing. This vulnerability arises when the dispatchRequest function normalizes inherited Object.prototype.headers from a manipulated configuration. As a result, trusted request interceptors may inadvertently return configurations that leak sensitive information, including authorization headers, making this a serious security concern for users of the affected versions. The issue has been resolved in version 1.20.0.

Affected Version(s)

axios >= 1.0.0, < 1.20.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.