Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.9 React GHSA-x97p-jq2g-jp4f CVE-2026-101909

Axios Prototype Pollution Gadget Affects toFormData Options (CVE-2026-101909)

Axios versions in the 0.28.0–0.34.0 and 1.15.1–1.20.0 ranges contain a prototype pollution gadget in toFormData that processes inherited serialization options, allowing altered field naming, forced request failures, or changed value handling when combined with a separate pollution flaw. Fixed versions 0.34.0 and 1.20.0 are available.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A newly published vulnerability affects Axios, a widely used promise-based HTTP client for browsers and Node.js. The issue, tracked as CVE-2026-101909 (GHSA-x97p-jq2g-jp4f), involves a prototype pollution gadget in the library's toFormData functionality. Because Axios is embedded in an enormous number of JavaScript and Node.js projects, this issue has broad potential reach, though exploitation depends on conditions outside Axios itself.

What happened

Axios's toFormData function was found to process serialization options and visitor properties that can be inherited through the object prototype rather than set directly. This means that if an attacker can pollute the prototype chain through a separate, independent vulnerability, the inherited values can influence how toFormData serializes objects. This gadget itself does not create the initial prototype pollution; it consumes pollution introduced elsewhere in the same process.

Technical cause

The vulnerability is classified as CWE-1321, Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution). According to the advisory, a separate same-process prototype-pollution flaw can supply inherited values for 'dots', 'indexes', 'metaTokens', 'maxDepth', 'visitor', or 'Blob' settings before object serialization occurs in toFormData. These inherited options can change field naming and how data is interpreted during serialization, cause maxDepth to force request failures, or alter how Blob values are handled. If an attacker already has the stronger capability to inject a function (a separate, more severe primitive), a polluted 'visitor' property could also be executed.

Why it matters

Axios is one of the most widely deployed HTTP client libraries in the JavaScript ecosystem, used in both browser and Node.js applications. A gadget that consumes prototype pollution to affect data serialization can lead to altered request data, denial of service through forced request failures, or changed value handling in affected applications. The practical impact in any given deployment depends on whether an independent prototype pollution vector exists elsewhere in the application or its dependencies, since this issue by itself is a gadget rather than a standalone pollution source.

Affected versions

Two separate affected ranges are documented: Axios versions from 0.28.0 up to but not including 0.34.0, and versions from 1.15.1 up to but not including 1.20.0. Versions outside these ranges, including releases prior to 0.28.0, are not listed as affected in the available data.

Fixes and mitigation

The vulnerability is fixed in Axios version 0.34.0 for the 0.x branch and version 1.20.0 for the 1.x branch. No mitigation details beyond upgrading are provided in the available facts.

Recommended action

Site owners and developers using Axios should check their dependency versions against the affected ranges (0.28.0–0.34.0 and 1.15.1–1.20.0) and upgrade to version 0.34.0 or 1.20.0 as appropriate. Because this issue acts as a gadget for prototype pollution introduced elsewhere, organizations should also review their applications and other dependencies for independent prototype pollution vulnerabilities that could be chained with this one.

PatchBriefing score

5.9 / 10 · Medium

Official CVSS: 8.3

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

This issue carries a PatchBriefing score of 5.9, driven primarily by a CVSS base score of 8.3, which contributes the largest share of the score. Additional minor contributions come from the fact that the vulnerability can be triggered without authentication and without user interaction, and from Axios's very high product popularity. The score does not include any contribution from known exploitation, public exploit availability, or EPSS, as none of these factors were elevated in the available data. A fix is available, which also means no penalty was applied for a missing patch.

Affected versions

axios >= 1.15.1, < 1.20.0
vulnerable
≥ 0.34.0
patched
≥ 1.20.0
patched

Reported fixes

The vulnerability is fixed in Axios version 0.34.0 for the 0.x branch and version 1.20.0 for the 1.x branch. No mitigation details beyond upgrading are provided in the available facts.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
Axios Prototype Pollution Gadget Affects toFormData Options (CVE-2026-101909)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email