CVE-2026-101905
Received Received - Intake

Axios Node HTTP Adapter Prototype Pollution in createConnection

Vulnerability report for CVE-2026-101905, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
axios axios 1.20.0
axios axios From 1.15.2 (inc) to 1.20.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype-pollution flaw in Axios's Node HTTP adapter. It allows an attacker to hijack request sockets by polluting the Object.prototype.createConnection property. When Axios creates a null-prototype options object, Node.js later copies it into a regular object, enabling access to inherited properties. If createConnection is polluted, Node.js will call the attacker-controlled function to establish a socket connection, redirecting requests to an attacker-controlled endpoint while the URL appears legitimate.

Detection Guidance

Check if your application uses Axios versions between 1.15.2 and 1.20.0. Inspect Node.js processes for prototype pollution in Object.prototype.createConnection. Monitor network traffic for unexpected socket connections or data exfiltration.

Impact Analysis

This vulnerability can allow attackers to intercept sensitive data such as Authorization headers, cookies, API keys, and service credentials. They can also return malicious responses while the URL appears legitimate. It affects Node.js HTTP/HTTPS requests using Axios where createConnection is not explicitly set, particularly in processes with prior prototype pollution.

Compliance Impact

This vulnerability could lead to unauthorized interception of sensitive data such as credentials, API keys, or cookies during HTTP requests. For GDPR, this may violate principles of data protection and confidentiality, potentially leading to unauthorized access to personal data. Under HIPAA, exposure of protected health information (PHI) through credential theft or response manipulation could result in compliance violations and breaches.

Mitigation Strategies

Upgrade Axios to version 1.20.0 or later. Explicitly set createConnection: undefined in Axios HTTP adapter options. Review and sanitize all user-controlled input to prevent prototype pollution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101905. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart