CVE-2026-101902 Overview
CVE-2026-101902 is a prototype pollution gadget [CWE-1321] in the Axios HTTP client library for browsers and Node.js. Axios default-instance requests that omit an explicit method can read an inherited value from Object.prototype. When another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can dispatch a state-changing HTTP method instead of the expected default GET. Axios does not introduce the pollution source; it acts as a read-side gadget in request dispatch. Affected versions include 0.27.2 through 0.33.x and 1.x prior to 1.20.0.
Critical Impact
Attackers who can pollute Object.prototype.method in a Node.js or browser process can convert Axios GET requests into arbitrary state-changing HTTP methods, enabling unintended writes, deletes, or CSRF-style actions against downstream APIs.
Affected Products
- Axios 0.27.2 through versions prior to 0.34.0
- Axios 1.x versions prior to 1.20.0
- Node.js and browser applications using the default Axios instance without an explicit method
Discovery Timeline
- 2026-09-28 - CVE-2026-101902 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-101902
Vulnerability Analysis
Axios dispatches requests through lib/core/Axios.js, which normalizes the outgoing HTTP method using a chained OR expression. The pre-patch logic read config.method || this.defaults.method || 'get' directly from the objects, which resolves inherited properties through the prototype chain. If Object.prototype.method is set elsewhere in the process, both config.method and this.defaults.method inherit that value, and Axios uses it as the outgoing HTTP verb.
The result is a request dispatch primitive that turns intended GET calls into arbitrary methods such as POST, PUT, or DELETE. Application code that assumes a read-only Axios call becomes a state-changing request against the target API, bypassing developer assumptions around request safety.
Root Cause
The root cause is unsafe property access on user-influenced objects. Axios trusted own-and-inherited property lookups when resolving the request method, satisfying the definition of a prototype pollution gadget under [CWE-1321]. Axios itself does not pollute the prototype; it consumes a polluted state introduced by another component in the same JavaScript realm.
Attack Vector
Exploitation requires a separate prototype pollution primitive in the same process, for example an unsafe deep-merge, Object.assign on attacker-controlled JSON, or a vulnerable dependency. Once Object.prototype.method = 'delete' (or any verb) is set, any subsequent axios({ url }) or axios.request({ url }) call that omits method dispatches with that verb. The attack has network reach because polluted values propagate to every request the process issues.
// Patch: lib/core/Axios.js — safe property access on method resolution
// Before:
// config.method = (config.method || this.defaults.method || 'get').toLowerCase();
// After:
config.method = (
utils.getSafeProp(config, 'method') ||
utils.getSafeProp(this.defaults, 'method') ||
'get'
).toLowerCase();
headers &&
utils.forEach(
['delete', 'get', 'head', 'post', 'put', 'patch', 'query', 'common'],
(method) => {
delete headers[method];
}
);
Source: GitHub Axios Commit d19040b
Detection Methods for CVE-2026-101902
Indicators of Compromise
- Unexpected non-GET HTTP methods issued by services that rely on Axios defaults, especially DELETE, PUT, or PATCH to endpoints that normally receive only reads.
- Application error spikes from downstream APIs rejecting mismatched verbs against read-oriented routes.
- Presence of vulnerable Axios versions (0.27.2–0.33.x, 1.0.0–1.19.x) in package-lock.json or yarn.lock.
Detection Strategies
- Perform software composition analysis (SCA) across Node.js projects and container images to enumerate Axios versions and flag those below 0.34.0 or 1.20.0.
- Add runtime assertions or middleware that logs the resolved HTTP method for outbound Axios calls in high-value services.
- Scan source code for patterns such as axios({ url }) and axios.request({ url }) where method is omitted, and require explicit verbs in code review.
Monitoring Recommendations
- Alert on egress web proxy logs when application identities issue state-changing verbs to endpoints not present in the expected API contract.
- Correlate prototype pollution advisories in dependencies with services using Axios, since exploitation of this gadget requires a paired pollution primitive.
- Track dependency drift in CI/CD pipelines and fail builds when Axios resolves to a vulnerable version.
How to Mitigate CVE-2026-101902
Immediate Actions Required
- Upgrade Axios to 0.34.0 for the 0.x branch or 1.20.0 for the 1.x branch across all applications and container images.
- Audit dependencies for known prototype pollution vulnerabilities and remediate them; the Axios gadget is only exploitable when Object.prototype.method is polluted.
- Explicitly set method on every Axios call, even when the intent is GET, to eliminate reliance on inherited defaults.
Patch Information
The fix replaces direct property lookups with utils.getSafeProp, which returns only own properties and ignores values inherited from Object.prototype. It ships in Axios v0.34.0 and v1.20.0. See the GitHub Security Advisory GHSA-9fr6-4gfg-395g and Pull Request #11141 for the full patch.
Workarounds
- Freeze Object.prototype at process startup with Object.freeze(Object.prototype) to prevent pollution from downstream dependencies.
- Wrap Axios calls in a helper that forces method: 'get' (or the intended verb) before dispatch, overriding any inherited value.
- Use Object.create(null) or validated schemas when constructing config objects passed to Axios to avoid inheriting prototype properties.
# Upgrade Axios to a patched release
npm install axios@^1.20.0
# or, for the 0.x branch
npm install axios@0.34.0
# Verify the resolved version
npm ls axios
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.