Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101908

6.9MEDIUM

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101908?

A vulnerability in the Axios HTTP client versions 1.7.0 to 1.20.0 allows attacker-controlled request headers to alter authorization, caching, and application behavior. The fetch adapter incorrectly constructs a Request with sanitized options but uses original fetchOptions when invoking the fetch method. This behavior can lead to altered request headers through JavaScript prototype inheritance. To mitigate this issue, users should upgrade to version 1.20.0, where the flaw has been addressed.

Affected Version(s)

axios >= 1.7.0, < 1.20.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.