Prototype Pollution Vulnerability in Axios HTTP Client for Node.js
CVE-2026-101905
7.6HIGH
What is CVE-2026-101905?
A vulnerability in the Axios HTTP client for Node.js exposes systems to prototype pollution through the Node HTTP adapter. The flaw arises from the absence of a secure createConnection value, allowing attackers to exploit a prototype pollution vulnerability. By placing a function on Object.prototype.createConnection, an attacker can intercept HTTP requests, gaining access to sensitive request headers and bodies, including user credentials. The attacker can respond with malicious content while the URL remains seemingly legitimate, posing serious security risks. This vulnerability was resolved in Axios version 1.20.0, which is recommended for all users.
Affected Version(s)
axios >= 1.15.2, < 1.20.0
