CVE-2026-101908: Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
axiosto a version that resolves this vulnerability.Fixed in 1.20.0
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker must be able to exploit a separate prototype-pollution issue in the same process to populate Object.prototype.headers. The vulnerable fetch adapter must then make an outbound request using fetchOptions that inherits that attacker-controlled headers value.
Which Axios versions need remediation?
Axios versions from 1.7.0 up to, but not including, 1.20.0 are affected. Upgrade to version 1.20.0 to obtain the fix.
What can an attacker change through this issue?
Attacker-controlled inherited headers can override the sanitized headers when fetch is called. This can affect authorization, caching, metadata-service access, or application-specific behavior of outbound requests.