Prototype Pollution in Axios HTTP Client Impacts Multiple Versions
CVE-2026-101904
6.9MEDIUM
What is CVE-2026-101904?
In Axios, a promise-based HTTP client, versions from 1.0.0 to 1.20.0 are susceptible to a prototype pollution issue that allows attacker-controlled headers to be resolved and exposed during request processing. This vulnerability arises when the dispatchRequest function normalizes inherited Object.prototype.headers from a manipulated configuration. As a result, trusted request interceptors may inadvertently return configurations that leak sensitive information, including authorization headers, making this a serious security concern for users of the affected versions. The issue has been resolved in version 1.20.0.
Affected Version(s)
axios >= 1.0.0, < 1.20.0
