CVE-2026-101909
Received Received - Intake

Prototype Pollution in Axios HTTP Client

Vulnerability report for CVE-2026-101909, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFormData processes inherited serialization options and visitor properties supplied through prototype pollution. A separate same-process prototype-pollution flaw supplies inherited dots, indexes, metaTokens, maxDepth, visitor, or Blob values before object serialization. The inherited options alter toFormData field naming and data interpretation, maxDepth can force request failure, Blob changes value handling, and a polluted visitor can execute when an attacker already has the stronger ability to inject a function. Serialized field naming and data interpretation can change, maxDepth can cause request failure, Blob can alter value handling, and a polluted visitor can execute under the stronger function-injection primitive. This issue is fixed in versions 0.34.0 and 1.20.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
axios axios to 0.34.0 (inc)
axios axios to 1.20.0 (inc)
axios axios From 0.28.0 (inc)
axios axios From 1.15.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a prototype pollution vulnerability in the Axios library affecting versions between 0.28.0-0.34.0 and 1.15.1-1.20.0. It occurs in the form data serialization logic where Axios reads properties like visitor, maxDepth, dots, indexes, metaTokens, and Blob from an internal options object without proper checks. If Object.prototype is polluted elsewhere in the same process, these inherited values can alter how Axios serializes multipart and URL-encoded request bodies.

Detection Guidance

Check Axios version in your project dependencies using npm list axios or grep -r 'axios' package.json. Versions between 0.28.0-0.33.x and 1.15.1-1.19.x are vulnerable. Inspect network requests for malformed form data or unexpected field names that may indicate prototype pollution affecting serialization.

Impact Analysis

The impact varies based on the polluted property. It can change field naming formats in request bodies, causing receiving services to parse different data than intended. A polluted maxDepth can trigger errors leading to denial of service. The most severe case involves polluting visitor, which executes a function during serialization, potentially exfiltrating sensitive data like passwords or tokens.

Compliance Impact

This vulnerability can lead to data exfiltration, which directly impacts compliance with GDPR (data protection) and HIPAA (health data privacy). Unauthorized access to sensitive data violates confidentiality requirements and may result in regulatory penalties or breaches of compliance standards.

Mitigation Strategies

Upgrade Axios to version 0.34.0 or 1.20.0 or later. If immediate upgrade is not possible, avoid passing user-controlled objects to form serialization functions and explicitly define safe formSerializer options with all properties set.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101909. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart