PT-2026-99947 · Npm · Axios

·

CVE-2026-101904

·

Published

2026-08-12

·

Updated

2026-09-30

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Axios versions 1.0.0 through 1.19.x
Description The dispatchRequest() function normalizes inherited Object.prototype.headers from a replacement request configuration. When a same-process prototype pollution flaw sets Object.prototype.headers and trusted request interceptors return a new configuration lacking its own headers property, dispatchRequest() resolves the inherited headers during normalization. This allows downstream request processing to observe attacker-controlled headers, including authorization-related values. Prototype pollution is a vulnerability where an attacker can manipulate the prototype of a base object, causing all objects inheriting from that prototype to have the injected properties.
Recommendations Update to version 1.20.0.

Exploit

Fix

Prototype Pollution

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-105257
BDU:2026-15722
CVE-2026-101904
GHSA-J8RH-479H-CP32

Affected Products

Axios