Skip to main content
Vulnerability Database/CVE-2026-101902

CVE-2026-101902: Axios HTTP Client Prototype Pollution Gadget

CVE-2026-101902 is a prototype pollution gadget in Axios HTTP client affecting versions 0.27.2 to 0.34.0 and 1.20.0. Attackers can exploit inherited method values to send unintended HTTP requests. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-101902 Overview

CVE-2026-101902 is a prototype pollution gadget [CWE-1321] in the Axios HTTP client library for browsers and Node.js. Axios default-instance requests that omit an explicit method can read an inherited value from Object.prototype. When another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can dispatch a state-changing HTTP method instead of the expected default GET. Axios does not introduce the pollution source; it acts as a read-side gadget in request dispatch. Affected versions include 0.27.2 through 0.33.x and 1.x prior to 1.20.0.

Critical Impact

Attackers who can pollute Object.prototype.method in a Node.js or browser process can convert Axios GET requests into arbitrary state-changing HTTP methods, enabling unintended writes, deletes, or CSRF-style actions against downstream APIs.

Affected Products

  • Axios 0.27.2 through versions prior to 0.34.0
  • Axios 1.x versions prior to 1.20.0
  • Node.js and browser applications using the default Axios instance without an explicit method

Discovery Timeline

  • 2026-09-28 - CVE-2026-101902 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-101902

Vulnerability Analysis

Axios dispatches requests through lib/core/Axios.js, which normalizes the outgoing HTTP method using a chained OR expression. The pre-patch logic read config.method || this.defaults.method || 'get' directly from the objects, which resolves inherited properties through the prototype chain. If Object.prototype.method is set elsewhere in the process, both config.method and this.defaults.method inherit that value, and Axios uses it as the outgoing HTTP verb.

The result is a request dispatch primitive that turns intended GET calls into arbitrary methods such as POST, PUT, or DELETE. Application code that assumes a read-only Axios call becomes a state-changing request against the target API, bypassing developer assumptions around request safety.

Root Cause

The root cause is unsafe property access on user-influenced objects. Axios trusted own-and-inherited property lookups when resolving the request method, satisfying the definition of a prototype pollution gadget under [CWE-1321]. Axios itself does not pollute the prototype; it consumes a polluted state introduced by another component in the same JavaScript realm.

Attack Vector

Exploitation requires a separate prototype pollution primitive in the same process, for example an unsafe deep-merge, Object.assign on attacker-controlled JSON, or a vulnerable dependency. Once Object.prototype.method = 'delete' (or any verb) is set, any subsequent axios({ url }) or axios.request({ url }) call that omits method dispatches with that verb. The attack has network reach because polluted values propagate to every request the process issues.

javascript
// Patch: lib/core/Axios.js — safe property access on method resolution
// Before:
//   config.method = (config.method || this.defaults.method || 'get').toLowerCase();
// After:
config.method = (
  utils.getSafeProp(config, 'method') ||
  utils.getSafeProp(this.defaults, 'method') ||
  'get'
).toLowerCase();

headers &&
  utils.forEach(
    ['delete', 'get', 'head', 'post', 'put', 'patch', 'query', 'common'],
    (method) => {
      delete headers[method];
    }
  );

Source: GitHub Axios Commit d19040b

Detection Methods for CVE-2026-101902

Indicators of Compromise

  • Unexpected non-GET HTTP methods issued by services that rely on Axios defaults, especially DELETE, PUT, or PATCH to endpoints that normally receive only reads.
  • Application error spikes from downstream APIs rejecting mismatched verbs against read-oriented routes.
  • Presence of vulnerable Axios versions (0.27.2–0.33.x, 1.0.0–1.19.x) in package-lock.json or yarn.lock.

Detection Strategies

  • Perform software composition analysis (SCA) across Node.js projects and container images to enumerate Axios versions and flag those below 0.34.0 or 1.20.0.
  • Add runtime assertions or middleware that logs the resolved HTTP method for outbound Axios calls in high-value services.
  • Scan source code for patterns such as axios({ url }) and axios.request({ url }) where method is omitted, and require explicit verbs in code review.

Monitoring Recommendations

  • Alert on egress web proxy logs when application identities issue state-changing verbs to endpoints not present in the expected API contract.
  • Correlate prototype pollution advisories in dependencies with services using Axios, since exploitation of this gadget requires a paired pollution primitive.
  • Track dependency drift in CI/CD pipelines and fail builds when Axios resolves to a vulnerable version.

How to Mitigate CVE-2026-101902

Immediate Actions Required

  • Upgrade Axios to 0.34.0 for the 0.x branch or 1.20.0 for the 1.x branch across all applications and container images.
  • Audit dependencies for known prototype pollution vulnerabilities and remediate them; the Axios gadget is only exploitable when Object.prototype.method is polluted.
  • Explicitly set method on every Axios call, even when the intent is GET, to eliminate reliance on inherited defaults.

Patch Information

The fix replaces direct property lookups with utils.getSafeProp, which returns only own properties and ignores values inherited from Object.prototype. It ships in Axios v0.34.0 and v1.20.0. See the GitHub Security Advisory GHSA-9fr6-4gfg-395g and Pull Request #11141 for the full patch.

Workarounds

  • Freeze Object.prototype at process startup with Object.freeze(Object.prototype) to prevent pollution from downstream dependencies.
  • Wrap Axios calls in a helper that forces method: 'get' (or the intended verb) before dispatch, overriding any inherited value.
  • Use Object.create(null) or validated schemas when constructing config objects passed to Axios to avoid inheriting prototype properties.
bash
# Upgrade Axios to a patched release
npm install axios@^1.20.0
# or, for the 0.x branch
npm install axios@0.34.0

# Verify the resolved version
npm ls axios

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.