Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101908
6.9MEDIUM
What is CVE-2026-101908?
A vulnerability in the Axios HTTP client versions 1.7.0 to 1.20.0 allows attacker-controlled request headers to alter authorization, caching, and application behavior. The fetch adapter incorrectly constructs a Request with sanitized options but uses original fetchOptions when invoking the fetch method. This behavior can lead to altered request headers through JavaScript prototype inheritance. To mitigate this issue, users should upgrade to version 1.20.0, where the flaw has been addressed.
Affected Version(s)
axios >= 1.7.0, < 1.20.0
