Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101909
What is CVE-2026-101909?
The Axios HTTP client, a popular promise-based library for browsers and Node.js, is vulnerable to a prototype pollution issue that affects specific versions. This flaw allows crafted serialized data to modify field naming and data interpretation during the conversion process in the toFormData function. An attacker could exploit this vulnerability by manipulating inherited serialization options, affecting overall request integrity. The issue may lead to request failures and unintended data handling consequences when parameters such as maxDepth or Blob values are improperly processed. This vulnerability has been addressed in Axios versions 0.34.0 and 1.20.0, where updates mitigate the risk by ensuring secure data serialization.
Affected Version(s)
axios >= 1.15.1, < 1.20.0 < 1.15.1, 1.20.0
axios >= 0.28.0, < 0.34.0 < 0.28.0, 0.34.0
