๐Ÿ” CVE Alert

CVE-2026-101902

UNKNOWN 0.0

Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.

CWE CWE-1321
Vendor axios
Product axios
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
>= 1.0.0, < 1.20.0 >= 0.27.2, < 0.34.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g github.com: https://github.com/axios/axios/pull/11141 github.com: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a github.com: https://github.com/axios/axios/releases/tag/v0.34.0 github.com: https://github.com/axios/axios/releases/tag/v1.20.0