Skip to main content
Vulnerability Database/CVE-2026-101900

CVE-2026-101900: Axios HTTP Client Header Injection Vulnerability

CVE-2026-101900 is a header injection flaw in Axios HTTP client that allows attackers to control request headers through prototype pollution. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-101900 Overview

CVE-2026-101900 affects Axios, a promise-based HTTP client for the browser and Node.js. The flaw exists in resolveConfig between versions 1.12.0 and 1.20.0. The function reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. When combined with a separate same-process prototype-pollution flaw, an attacker can supply an array or non-plain class instance whose inherited properties make it appear FormData-like. The inherited getHeaders function then returns attacker-controlled headers that resolveConfig merges into a fetch adapter request. This categorizes as an improper input validation issue tracked under [CWE-74].

Critical Impact

Attacker-controlled headers can modify authorization, cache, metadata-service, or application-specific request behavior in outbound HTTP requests issued by Axios.

Affected Products

  • Axios versions 1.12.0 through 1.19.x (Node.js and browser)
  • Applications using the Axios fetch adapter with FormData-like payloads
  • Node.js services chaining Axios with third-party libraries susceptible to prototype pollution

Discovery Timeline

  • 2026-09-28 - CVE-2026-101900 published to NVD
  • 2026-09-30 - Last updated in NVD database
  • Fixed release - Axios v1.20.0 published on GitHub with hardened runtime option handling

Technical Details for CVE-2026-101900

Vulnerability Analysis

The vulnerability lives in the FormData resolution path used by the Axios fetch adapter. During request preparation, resolveConfig inspects the request body to determine whether it is FormData-like. That check reads inherited properties (Symbol.toStringTag, append, and getHeaders) rather than restricting itself to own properties on plain objects. Because plain objects are explicitly blocked but arrays and class instances are not, an object polluted through the JavaScript prototype chain can bypass the guard. When Axios then invokes the inherited getHeaders function, it receives attacker-controlled key-value pairs and merges them into the outgoing request. The resulting request can carry forged Authorization, Cookie, cache directives, or cloud metadata-service headers, altering downstream trust decisions.

Root Cause

The root cause is unsafe property lookup during type detection. The resolveConfig logic relied on presence of methods reached via the prototype chain to identify FormData objects. Combined with a second, external prototype-pollution flaw in the host process, this allows a non-plain object to satisfy the FormData duck-typing check and inject inherited functions that return attacker-defined header maps.

Attack Vector

Exploitation requires an attacker to first achieve same-process prototype pollution and then trigger an Axios request that treats a polluted array or class instance as FormData. The attack does not require authentication and executes as part of normal application flow, but it depends on the presence of a separate prototype-pollution primitive in the target application or its dependencies.

javascript
// Security patch in lib/core/Axios.js - fix: harden runtime option handling (#11141)
// Uses utils.getSafeProp to avoid reading inherited/polluted properties

// Set config.method
config.method = (
  utils.getSafeProp(config, 'method') ||
  utils.getSafeProp(this.defaults, 'method') ||
  'get'
).toLowerCase();

// Flatten headers
let contextHeaders = headers && utils.merge(headers.common, headers[config.method]);

headers &&
  utils.forEach(
    ['delete', 'get', 'head', 'post', 'put', 'patch', 'query', 'common'],
    (method) => {
      delete headers[method];
    }
  );

config.headers = AxiosHeaders.concat(contextHeaders, headers);

Source: GitHub Commit d19040b

Detection Methods for CVE-2026-101900

Indicators of Compromise

  • Unexpected Authorization, Cookie, or X-Amz-* headers on outbound requests from Node.js services using Axios
  • Outbound requests to cloud instance metadata endpoints such as 169.254.169.254 from application processes that do not normally query them
  • Anomalous cache-control or referrer headers that diverge from application defaults on Axios traffic

Detection Strategies

  • Inventory installed Axios versions with npm ls axios and flag any version in the range >=1.12.0 <1.20.0
  • Audit application code and dependencies for prototype-pollution sinks (Object.assign, recursive merge utilities, unsafe query-string parsers)
  • Instrument HTTP egress to log full header sets from Node.js runtimes and compare against expected header baselines

Monitoring Recommendations

  • Alert on outbound HTTP requests to cloud metadata IPs from workloads that do not need metadata access
  • Monitor SCA (Software Composition Analysis) findings for GHSA-4hqw-qxg8-jxx2 across CI/CD pipelines
  • Correlate application logs with egress proxy logs to surface header values injected outside the application's control flow

How to Mitigate CVE-2026-101900

Immediate Actions Required

  • Upgrade Axios to version 1.20.0 or later across all Node.js and browser bundles
  • Identify and remediate any prototype-pollution vulnerabilities in application code and transitive dependencies
  • Restrict outbound network access from application workloads to cloud metadata endpoints using IMDSv2 or network policy

Patch Information

The fix is available in Axios v1.20.0. The patch introduces utils.getSafeProp for safe own-property access and adds a DEFAULT_REQUEST_OPTIONS object in the fetch adapter to prevent inherited properties from influencing request configuration. See the GitHub Security Advisory GHSA-4hqw-qxg8-jxx2, the GitHub Release v1.20.0, and the GitHub Pull Request Discussion for full context.

Workarounds

  • Freeze Object.prototype at process start using Object.freeze(Object.prototype) where compatible
  • Validate that request bodies passed to Axios are own-property plain objects or genuine FormData instances before dispatch
  • Wrap Axios calls in a helper that strips inherited properties from configuration objects prior to invocation
bash
# Upgrade Axios to the patched version
npm install axios@^1.20.0

# Verify no vulnerable versions remain in the dependency tree
npm ls axios

# Audit for known advisories
npm audit --production

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.