PT-2026-99939 · Npm · Axios

·

CVE-2026-101900

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Axios versions 1.12.0 through 1.19.x
Description While resolving FormData headers, the ResolveConfig function reads inherited Symbol.toStringTag, append, and getHeaders properties. A prototype pollution flaw allows an attacker to provide an array or non-plain class instance that mimics FormData. Consequently, the inherited getHeaders() function can return attacker-controlled headers that are merged into a fetch adapter request, potentially altering authorization, cache, metadata-service, or application-specific request behavior.
Recommendations Update to version 1.20.0.

Exploit

Fix

Protection Mechanism Failure

Special Elements Injection

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101900
GHSA-4HQW-QXG8-JXX2

Affected Products

Axios