PT-2026-99948 · Npm · Axios

·

CVE-2026-101905

·

Published

2026-08-12

·

Updated

2026-10-01

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Axios versions 1.15.2 through 1.19.x
Description The Node HTTP adapter in lib/adapters/http.js provides request options that lack a specific createConnection value. When a separate prototype pollution flaw is present in the same process, an attacker can place a function on Object.prototype.createConnection. Node then resolves and executes this inherited socket factory, enabling the attacker to control the transport endpoint. This allows the attacker to intercept request headers and bodies, including credentials, and provide malicious responses while the URL remains seemingly legitimate.
Recommendations Update to version 1.20.0.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15727
CVE-2026-101905
GHSA-M8M8-QJ5V-23W3

Affected Products

Axios