CVE-2026-101905 Overview
CVE-2026-101905 affects Axios, a promise-based HTTP client for the browser and Node.js. Versions from 1.15.2 up to (but not including) 1.20.0 contain a flaw in the Node HTTP adapter (lib/adapters/http.js). The adapter passes request options without setting an own createConnection property. When a separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection, Node inherits and invokes that attacker-controlled socket factory. The attacker chooses the transport endpoint, receives request headers and bodies (including credentials), and returns arbitrary responses while the request URL still appears legitimate to the calling application. The issue is fixed in Axios 1.20.0.
Critical Impact
Attackers with a same-process prototype-pollution primitive can silently redirect outbound Axios traffic, exfiltrating credentials and injecting forged responses without altering the target URL.
Affected Products
- Axios for Node.js >=1.15.2, <1.20.0
- Server-side applications using the Axios Node HTTP adapter (lib/adapters/http.js)
- Node.js services that also expose or import a component vulnerable to prototype pollution in the same process
Discovery Timeline
- 2026-09-28 - CVE-2026-101905 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-101905
Vulnerability Analysis
Axios builds a request options object and hands it to Node's http.request or https.request. The Node HTTP client honors a createConnection option that lets callers supply a custom socket factory. The Axios adapter did not set an own createConnection value on the options object. As a result, Node's property lookup walked the prototype chain and picked up any inherited value.
When Object.prototype.createConnection is polluted with a function, every subsequent Axios request in that process routes through the attacker-controlled factory. That function chooses where the TCP or TLS connection actually terminates. The URL, Host header, and TLS Server Name Indication (SNI) values seen by application logic remain unchanged, so telemetry that inspects only the intended destination reports normal behavior [CWE-441: Unintended Proxy or Intermediary].
Root Cause
The root cause is unsafe reliance on prototype-chain lookup for a security-sensitive Node HTTP option. Because createConnection was neither explicitly set nor filtered by hasOwnProperty, a polluted prototype directly influenced transport selection. The fix in pull request #11141 hardens runtime option handling by using safe property accessors and defining an explicit default request-options set.
Attack Vector
Exploitation requires a coexisting prototype-pollution primitive reachable in the same Node.js process, for example through an unsafe merge, deep-copy, or JSON parser used elsewhere in the application or a dependency. Once Object.prototype.createConnection is set, any Axios call using the Node adapter becomes a covert man-in-the-middle channel. The attacker collects Authorization headers, session cookies, API keys, and request bodies, then returns forged responses that the application trusts.
// Excerpt from the security patch (lib/adapters/fetch.js)
// Source: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
const DEFAULT_CHUNK_SIZE = 64 * 1024;
const DEFAULT_REQUEST_OPTIONS = {
cache: 'default',
redirect: 'follow',
referrer: 'about:client',
referrerPolicy: '',
mode: 'cors',
integrity: '',
keepalive: false,
priority: 'auto',
window: null,
};
const { isFunction } = utils;
// Excerpt from the security patch (lib/core/Axios.js)
// Source: https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
// Set config.method using a safe property accessor that ignores prototype-chain values
config.method = (
utils.getSafeProp(config, 'method') ||
utils.getSafeProp(this.defaults, 'method') ||
'get'
).toLowerCase();
The patch introduces utils.getSafeProp to read only own properties and defines an explicit defaults object, preventing polluted prototypes from influencing runtime options.
Detection Methods for CVE-2026-101905
Indicators of Compromise
- Outbound TCP or TLS connections from a Node.js process to endpoints that do not match the hostnames present in application configuration or DNS resolution for the requested URLs.
- Runtime presence of Object.prototype.createConnection, Object.prototype.agent, or other polluted transport-related properties inspected via a live process dump or diagnostic script.
- Unexpected Authorization, Cookie, or bearer-token values appearing in traffic to unknown IP addresses.
Detection Strategies
- Inventory Node.js services and flag any application shipping Axios >=1.15.2, <1.20.0 in package-lock.json or yarn.lock.
- Use software composition analysis (SCA) rules that match the GitHub Security Advisory GHSA-m8m8-qj5v-23w3 identifier.
- Add runtime assertions at process start that check Object.prototype.hasOwnProperty('createConnection') and fail fast if true.
Monitoring Recommendations
- Correlate egress netflow with expected destination hostnames per service; alert on divergence between application-declared URL and resolved peer IP.
- Monitor Node.js processes for unexpected outbound TLS SNI values or connections to non-allowlisted ASNs.
- Ingest dependency and runtime telemetry into a SIEM to identify unpatched Axios versions across the fleet.
How to Mitigate CVE-2026-101905
Immediate Actions Required
- Upgrade Axios to version 1.20.0 or later across all Node.js services and rebuild container images.
- Audit the application and its dependency tree for prototype-pollution sinks, particularly unsafe Object.assign, deep-merge, and query-string parsers.
- Rotate credentials, API tokens, and session secrets that may have traversed an affected process during the exposure window.
Patch Information
The fix is delivered in Axios release v1.20.0 via pull request #11141 and commit d19040b. Details are documented in GHSA-m8m8-qj5v-23w3.
Workarounds
- If upgrade is not immediately possible, freeze Object.prototype at process start using Object.freeze(Object.prototype) after all trusted modules load.
- Wrap Axios instances to explicitly set createConnection and agent to safe defaults on every request configuration.
- Isolate outbound HTTP calls behind an egress proxy that enforces destination allowlists, so a hijacked socket factory cannot reach arbitrary endpoints.
# Upgrade Axios to the patched release
npm install axios@1.20.0 --save
# Verify no vulnerable versions remain in the resolved tree
npm ls axios
# Optional runtime guard added to the application entry point
node -e "Object.freeze(Object.prototype); require('./server.js');"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.