CVE-2026-101904
Received Received - Intake

Axios Prototype Pollution in HTTP Headers

Vulnerability report for CVE-2026-101904, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function normalizes inherited Object.prototype.headers from a replacement request configuration. A separate same-process prototype-pollution flaw sets Object.prototype.headers, and trusted request interceptors return a new ordinary configuration without an own headers property. After the interceptor chain, dispatchRequest resolves the inherited headers during normalization. Downstream request processing can observe attacker-controlled headers, including authorization-related values. This issue is fixed in version 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
axios axios to 1.20.0 (inc)
axios axios to 1.20.0 (exc)
axios axios From 1.20.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101904 is a prototype pollution vulnerability in the Axios library affecting versions 1.0.0 to 1.20.0. It allows attackers to inject headers into HTTP requests by exploiting how Axios handles inherited properties from Object.prototype. When a request interceptor returns a config without an explicit headers property, Axios may resolve and use polluted headers from Object.prototype.headers.

Detection Guidance

Check if your Axios version is below 1.20.0 by running npm list axios or checking package.json. Review interceptor implementations to ensure they set an explicit headers property. Monitor for unexpected headers in requests or responses.

Impact Analysis

This vulnerability can allow attackers to inject malicious headers into your HTTP requests, potentially bypassing authorization checks or manipulating cache behavior. It may impact routing logic, metadata services, or conditional requests in your application. The impact depends on how your application processes headers and handles requests.

Compliance Impact

This vulnerability could potentially affect compliance with GDPR and HIPAA by enabling unauthorized header injection, which may lead to improper handling of sensitive data. Attacker-controlled headers could manipulate authorization or routing logic, risking unauthorized access to protected information. The impact depends on how the application processes headers and whether intercepted requests involve regulated data.

Mitigation Strategies

Upgrade Axios to version 1.20.0 or later. Ensure interceptors always set an own headers property or return the merged config object without rebuilding it. Review and sanitize any prototype pollution vulnerabilities in your application.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101904. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart