PT-2026-99951 · Npm · Axios

·

CVE-2026-101908

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Axios versions 1.7.0 through 1.19.x
Description The fetch adapter constructs a Request using sanitized resolvedOptions but subsequently invokes fetch using the original fetchOptions. Due to a same-process prototype pollution flaw—where Object.prototype.headers is populated—the fetchOptions.headers value is resolved through inheritance. This inherited value overrides the sanitized Request headers via the second argument passed to fetch. Consequently, an attacker can control request headers to manipulate authorization, caching, metadata-service access, or application-specific behavior.
Recommendations Update to version 1.20.0.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101908
GHSA-VH66-26GQ-Q6X8

Affected Products

Axios