CVE-2026-101902
Received Received - Intake

Prototype Pollution Read Gadget in Axios HTTP Client

Vulnerability report for CVE-2026-101902, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
axios axios to 0.34.0 (inc)
axios axios 1.20.0
axios axios From 0.27.2 (inc)
axios axios 0.34.0
axios axios From 1.20.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype-pollution gadget in the Axios library. It allows an attacker to override the HTTP method in default-instance requests by polluting the Object.prototype.method property. If another vulnerability in the same process has already polluted Object.prototype.method, requests without an explicit method can be forced to use attacker-controlled methods like DELETE or POST instead of the expected GET method.

Detection Guidance

To detect this vulnerability, check if your Axios version is between 0.27.2 and 0.34.0 or 1.20.0. Run: npm list axios or node -e "console.log(require('axios/package.json').version)" to verify the installed version.

Impact Analysis

The impact depends on the target endpoint. It could lead to unintended writes, deletions, or other state changes if the HTTP method is treated as security-relevant. For example, a request intended as GET might instead execute as DELETE, causing data loss or unauthorized modifications.

Compliance Impact

This vulnerability could indirectly impact compliance with standards like GDPR and HIPAA by enabling unauthorized state-changing HTTP methods (e.g., POST, DELETE) in requests that should default to GET. If exploited, it may lead to unintended data modifications or deletions, violating integrity and access control requirements. However, the vulnerability itself does not directly violate these standards but creates a pathway for such violations if other prototype pollution vulnerabilities exist in the environment.

Mitigation Strategies

Upgrade Axios to version 0.34.0 or 1.20.0 or higher. Avoid using default-instance shorthand requests in environments where prototype pollution is possible. Use explicit method aliases like axios.get() or set an explicit method property in requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101902. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart