CVE-2026-101908
Received Received - Intake

Axios Fetch Adapter Prototype Pollution in Headers

Vulnerability report for CVE-2026-101908, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
axios axios From 1.7.0 (inc) to 1.20.0 (exc)
axios axios From 1.7.0 (inc) to 1.20.0 (inc)
axios axios 1.20.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Axios library versions 1.7.0 to 1.20.0. It involves a prototype pollution flaw in the fetch adapter where attacker-controlled headers can override sanitized request headers. The issue arises because fetchOptions inherits properties from Object.prototype, allowing malicious headers like Authorization to be injected or legitimate ones removed.

Detection Guidance

To detect this vulnerability, inspect your Axios usage for the fetch adapter in versions 1.7.0 to 1.20.0. Check for prototype pollution in your application by reviewing code that modifies Object.prototype. Monitor HTTP requests for unexpected header modifications or authorization bypasses.

Impact Analysis

An attacker could manipulate HTTP requests by altering headers, potentially bypassing security controls such as authorization checks. This could lead to unauthorized access, data leaks, or application-specific behavior changes. Exploitation requires prior prototype pollution in the same process.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling unauthorized header manipulation in HTTP requests. Attackers could inject malicious headers like Authorization to bypass security controls, access sensitive data, or alter application behavior, which may violate data protection requirements under these regulations.

Mitigation Strategies

Upgrade Axios to version 1.20.0 or later. If using the fetch adapter, switch to the Node HTTP adapter as a temporary workaround. Avoid passing empty fetchOptions objects in environments prone to prototype pollution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101908. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart