CVE-2026-101900
Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0.
| CWE | CWE-74 CWE-693 CWE-1321 |
| Vendor | axios |
| Product | axios |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Get instant alerts for axios axios
Be the first to know when new unknown vulnerabilities affecting axios axios are published โ delivered to Slack, Telegram or Discord.