Prototype Pollution Vulnerability in Axios HTTP Client for Node.js
CVE-2026-101905

7.6HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101905?

A vulnerability in the Axios HTTP client for Node.js exposes systems to prototype pollution through the Node HTTP adapter. The flaw arises from the absence of a secure createConnection value, allowing attackers to exploit a prototype pollution vulnerability. By placing a function on Object.prototype.createConnection, an attacker can intercept HTTP requests, gaining access to sensitive request headers and bodies, including user credentials. The attacker can respond with malicious content while the URL remains seemingly legitimate, posing serious security risks. This vulnerability was resolved in Axios version 1.20.0, which is recommended for all users.

Affected Version(s)

axios >= 1.15.2, < 1.20.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.