๐Ÿ” CVE Alert

CVE-2026-101908

UNKNOWN 0.0

Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0.

CWE CWE-1321
Vendor axios
Product axios
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for axios axios

Be the first to know when new unknown vulnerabilities affecting axios axios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

axios / axios
>= 1.7.0, < 1.20.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8 github.com: https://github.com/axios/axios/pull/11141 github.com: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a github.com: https://github.com/axios/axios/releases/tag/v1.20.0