Prototype Pollution Vulnerability in Axios HTTP Client
CVE-2026-101909

8.3HIGH

Key Information:

Vendor

AxiOS

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101909?

The Axios HTTP client, a popular promise-based library for browsers and Node.js, is vulnerable to a prototype pollution issue that affects specific versions. This flaw allows crafted serialized data to modify field naming and data interpretation during the conversion process in the toFormData function. An attacker could exploit this vulnerability by manipulating inherited serialization options, affecting overall request integrity. The issue may lead to request failures and unintended data handling consequences when parameters such as maxDepth or Blob values are improperly processed. This vulnerability has been addressed in Axios versions 0.34.0 and 1.20.0, where updates mitigate the risk by ensuring secure data serialization.

Affected Version(s)

axios >= 1.15.1, < 1.20.0 < 1.15.1, 1.20.0

axios >= 0.28.0, < 0.34.0 < 0.28.0, 0.34.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.