Skip to main content
Vulnerability Database/CVE-2026-101904

CVE-2026-101904: Axios Information Disclosure Vulnerability

CVE-2026-101904 is an information disclosure flaw in Axios HTTP client that allows attackers to control headers through prototype pollution. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-101904 Overview

CVE-2026-101904 affects Axios, a promise-based HTTP client for the browser and Node.js. Versions from 1.0.0 up to 1.20.0 normalize inherited Object.prototype.headers values inside the dispatchRequest function. When a separate same-process prototype-pollution flaw sets Object.prototype.headers, and a trusted request interceptor returns a new configuration object without its own headers property, dispatchRequest resolves the inherited headers during normalization. Downstream request processing then observes attacker-controlled headers, including authorization-related values. The issue is fixed in version 1.20.0 and is categorized under [CWE-74] Improper Neutralization of Special Elements in Output.

Critical Impact

Attackers who can pollute Object.prototype in the same process can inject arbitrary HTTP headers, including credentials, into outbound Axios requests.

Affected Products

  • Axios versions 1.0.0 through 1.19.x (Node.js and browser)
  • Applications using Axios request interceptors that return replacement configuration objects
  • Node.js services combining Axios with libraries susceptible to prototype pollution

Discovery Timeline

  • 2026-09-28 - CVE-2026-101904 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-101904

Vulnerability Analysis

Axios processes each request through an interceptor chain, then hands the resulting configuration to dispatchRequest. During normalization, dispatchRequest reads the headers property from the configuration object. JavaScript property lookups traverse the prototype chain when the property is not defined on the instance itself. If Object.prototype.headers has been assigned elsewhere in the process, and an interceptor returns a fresh object literal without its own headers key, the lookup resolves to the polluted prototype value.

The adapter then serializes those inherited headers into the outbound HTTP request. Attackers can inject Authorization, Cookie, or custom trust headers that downstream services accept as authentic. The flaw amplifies any co-resident prototype-pollution primitive into an authenticated-request forgery vector.

Root Cause

The root cause is unsafe property access on a configuration object whose prototype cannot be trusted. Axios code used direct property reads such as config.headers and config.method rather than own-property checks. When interceptors substitute a new plain object, own properties disappear, and prototype-chain values fill the gap.

Attack Vector

Exploitation requires a separate prototype-pollution primitive in the same Node.js process. Once Object.prototype.headers is set, any Axios request routed through an interceptor that returns a replacement configuration inherits the polluted headers. No network position or user interaction is required beyond triggering the polluted request path.

javascript
// Patched code in lib/core/Axios.js — uses safe own-property access
config.method = (
  utils.getSafeProp(config, 'method') ||
  utils.getSafeProp(this.defaults, 'method') ||
  'get'
).toLowerCase();

// Flatten headers
let contextHeaders = headers && utils.merge(headers.common, headers[config.method]);

headers &&
  utils.forEach(
    ['delete', 'get', 'head', 'post', 'put', 'patch', 'query', 'common'],
    (method) => {
      delete headers[method];
    }
  );

config.headers = AxiosHeaders.concat(contextHeaders, headers);

Source: GitHub Commit d19040b

Detection Methods for CVE-2026-101904

Indicators of Compromise

  • Outbound HTTP requests from Node.js services carrying unexpected Authorization, Cookie, or custom trust headers not set by application code.
  • Requests to internal APIs that succeed despite the calling context lacking the corresponding credential material.
  • Runtime evidence that Object.prototype has been mutated, such as unexpected enumerable properties on freshly created object literals.

Detection Strategies

  • Inventory Axios versions across Node.js services and flag any release below 1.20.0.
  • Add runtime assertions that verify Object.prototype has no own headers, method, or related properties at request-dispatch time.
  • Instrument HTTP client egress with header allow-lists so unexpected authorization headers trigger alerts.

Monitoring Recommendations

  • Forward Node.js process telemetry and outbound HTTP metadata to a centralized analytics tier for anomaly review.
  • Correlate spikes in authenticated internal API calls with recent deploys of vulnerable Axios versions.
  • Track dependency graphs continuously so new introductions of Axios < 1.20.0 are surfaced during code review.

How to Mitigate CVE-2026-101904

Immediate Actions Required

  • Upgrade Axios to version 1.20.0 or later across all Node.js and browser bundles.
  • Audit request interceptors for patterns that return new configuration objects without an explicit headers property.
  • Review dependencies for known prototype-pollution issues and remediate the upstream primitive.

Patch Information

The fix is included in the Axios v1.20.0 release and delivered through commit d19040b. The change introduces utils.getSafeProp for own-property access and defines a DEFAULT_REQUEST_OPTIONS object that the fetch adapter uses as a trusted baseline. Refer to the GHSA-j8rh-479h-cp32 advisory and the pull request #11141 for the complete change set.

Workarounds

  • Freeze Object.prototype early in process startup with Object.freeze(Object.prototype) when application code tolerates it.
  • Ensure interceptors preserve the original configuration by spreading known keys, including an explicit headers property.
  • Wrap Axios calls in a helper that validates outbound headers against an allow-list before dispatch.
bash
# Upgrade Axios to the patched release
npm install axios@^1.20.0

# Verify no vulnerable versions remain in the dependency tree
npm ls axios

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.