Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.1 React GHSA-j8rh-479h-cp32 CVE-2026-101904 GHSA-m8m8-qj5v-23w3 CVE-2026-101905

Axios: Two Vulnerabilities Allow Header and Socket Hijacking via Prototype Pollution Gadgets

Two related vulnerabilities in axios (CVE-2026-101904 and CVE-2026-101905) allow attacker-controlled data to leak through inherited Object.prototype properties, enabling header injection or request redirection. Both are fixed in axios 1.20.0.

AI summary

Two vulnerabilities have been published affecting axios, a widely used promise-based HTTP client for Node.js and browsers. Both issues, CVE-2026-101904 and CVE-2026-101905, depend on an inherited property from Object.prototype being resolved during request processing, allowing attacker-controlled data to influence requests in ways that can expose credentials or redirect traffic. Both are fixed in axios 1.20.0.

What happened

Two distinct advisories describe how axios's internal request handling can resolve properties inherited from Object.prototype instead of properties explicitly set on a request configuration object. In CVE-2026-101904, the dispatchRequest function normalizes headers and can pick up an inherited 'headers' property placed on Object.prototype, even after trusted request interceptors have returned a clean configuration object. This can expose attacker-controlled header values, including authorization-related data, to downstream request processing. In CVE-2026-101905, the Node HTTP adapter (lib/adapters/http.js) can resolve an inherited 'createConnection' function from Object.prototype when request options do not define their own createConnection value. Node then invokes this inherited function as the socket factory, letting an attacker-controlled function choose the actual network endpoint the request connects to, while the request's URL continues to appear legitimate.

Technical cause

Both issues depend on a separate, same-process prototype-pollution flaw that sets a property (headers or createConnection) on Object.prototype. Axios itself does not pollute the prototype; rather, once Object.prototype has been polluted by another component or code path running in the same process, axios's normalization and adapter logic fails to distinguish between a configuration object's own properties and properties inherited through the prototype chain. CVE-2026-101904 is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component). CVE-2026-101905 is classified as CWE-441 (Unintended Proxy or Intermediary / 'Confused Deputy').

Why it matters

CVE-2026-101904 carries a CVSS score of 6.9 and can result in attacker-controlled HTTP headers, including authorization-related values, reaching downstream systems. CVE-2026-101905 carries a CVSS score of 7.6 and is more severe in impact: it allows an attacker-controlled function to redirect the actual network connection to an endpoint of the attacker's choosing, letting that endpoint observe request headers and bodies (including credentials) and return fabricated responses, all while the request's intended URL appears unchanged. Both issues require a separate prototype-pollution condition to exist in the same process as a precondition; axios's flaw is in how it fails to guard against inherited properties once that precondition is met.

Affected versions

CVE-2026-101904 affects axios from version 1.0.0 up to, but not including, 1.20.0. CVE-2026-101905 affects axios from version 1.15.2 up to, but not including, 1.20.0. Both issues are fixed in axios 1.20.0.

Fixes and mitigation

Both vulnerabilities are fixed in axios 1.20.0. The fact package does not provide details on what specific code changes were made in the fix beyond the version number. There is no information provided on alternative mitigations for environments that cannot immediately upgrade.

Recommended action

Upgrade axios to version 1.20.0 or later. Because both vulnerabilities require a separate prototype-pollution condition elsewhere in the same process to be exploitable, organizations should also review their dependency tree and application code for any component capable of writing to Object.prototype, as that is the underlying precondition enabling both issues.

PatchBriefing score

5.1 / 10 · Medium

Official CVSS: 6.9

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

CVE-2026-101904 has a CVSS score of 6.9 and a patchwire score of 5.1, reflecting a moderate base severity combined with unauthenticated remote reachability and no required user interaction, but no evidence of known exploitation or a public exploit. CVE-2026-101905 has a higher CVSS score of 7.6 but a slightly lower patchwire score of 4.9, since it does not meet the unauthenticated-remote scoring criterion in this package despite requiring no user interaction. Neither vulnerability is listed as known exploited, associated with ransomware campaigns, or has a public exploit available. EPSS data was null for both in the top-level fields, though claim-level EPSS values of 0.00428 (CVE-2026-101904) and 0.00289 (CVE-2026-101905) indicate a low predicted likelihood of near-term exploitation. Both scores incorporate a product-popularity contribution reflecting axios's wide usage.

Affected versions

axios >= 1.0.0, < 1.20.0
vulnerable
≥ 1.20.0
patched
axios >= 1.15.2, < 1.20.0
vulnerable
≥ 1.20.0
patched

Reported fixes

Both vulnerabilities are fixed in axios 1.20.0. The fact package does not provide details on what specific code changes were made in the fix beyond the version number. There is no information provided on alternative mitigations for environments that cannot immediately upgrade.

How this was built

4 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Axios: Two Vulnerabilities Allow Header and Socket Hijacking via Prototype Pollution Gadgets
1 article · 4 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email