CVE-2026-101909 Overview
CVE-2026-101909 is a prototype pollution vulnerability [CWE-1321] in Axios, a promise-based HTTP client for the browser and Node.js. The flaw affects toFormData processing, where inherited serialization options and visitor properties supplied through prototype pollution alter request handling. Attackers can modify serialized field naming, force request failures via maxDepth, change value handling through Blob, or execute a polluted visitor when combined with function-injection capabilities. The issue affects Axios versions 0.28.0 through 0.34.0 and 1.15.1 through 1.20.0.
Critical Impact
A same-process prototype pollution flaw can alter Axios request serialization, trigger denial of service via maxDepth, and enable code execution when combined with function-injection primitives.
Affected Products
- Axios versions 0.28.0 through 0.33.x (fixed in 0.34.0)
- Axios versions 1.15.1 through 1.19.x (fixed in 1.20.0)
- Node.js and browser applications using Axios toFormData serialization
Discovery Timeline
- 2026-09-28 - CVE-2026-101909 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-101909
Vulnerability Analysis
The vulnerability resides in Axios's toFormData helper, which reads serialization options via property lookups that traverse the prototype chain. When a separate same-process prototype pollution flaw contaminates Object.prototype, inherited values for dots, indexes, metaTokens, maxDepth, visitor, or Blob are silently consumed during serialization.
These inherited options change how form fields are named and how values are interpreted. Setting maxDepth to a small value forces the serializer to reject legitimate requests, producing denial of service. A polluted Blob reference alters value handling, while a polluted visitor function executes during serialization when an attacker already possesses the stronger primitive of injecting a function through prototype pollution.
Root Cause
Axios read configuration properties using plain object access rather than own-property checks. This allowed inherited properties from a polluted Object.prototype to override caller-supplied or default configuration. Related option-resolution paths in lib/core/Axios.js, lib/adapters/http.js, and lib/adapters/fetch.js also failed to isolate merged config from the prototype chain, extending the impact to redirect hooks and request options.
Attack Vector
Exploitation requires a pre-existing prototype pollution primitive in the same process. Once Object.prototype is contaminated, any subsequent Axios call using toFormData inherits the attacker-controlled options. The following patch excerpts show how the maintainers hardened option resolution.
// Patch: lib/core/Axios.js — use own-property lookup for method resolution
// Set config.method
config.method = (
utils.getSafeProp(config, 'method') ||
utils.getSafeProp(this.defaults, 'method') ||
'get'
).toLowerCase();
Source: GitHub commit d19040b
// Patch: lib/adapters/http.js — null-prototype object for beforeRedirects
// dispatchBeforeRedirect calls whatever it finds here, and
// a plain object left an inherited function reachable
// and able to rewrite the redirect target.
beforeRedirects: Object.create(null)
Source: GitHub commit d29be18
Detection Methods for CVE-2026-101909
Indicators of Compromise
- Unexpected changes in outbound HTTP request field naming or serialization structure originating from Node.js processes using Axios.
- Runtime errors from Axios toFormData indicating maxDepth exceeded on requests that previously succeeded.
- Execution of unexpected functions during Axios request serialization traced back to Object.prototype writes.
Detection Strategies
- Inventory application dependencies using Software Composition Analysis (SCA) to identify Axios versions in the vulnerable ranges 0.28.0–0.33.x and 1.15.1–1.19.x.
- Add runtime assertions or use Object.freeze(Object.prototype) in test environments to surface prototype pollution attempts during CI.
- Monitor Node.js processes for unusual child-process spawns or outbound connections initiated during HTTP client activity.
Monitoring Recommendations
- Alert on dependency manifests (package.json, package-lock.json) that resolve Axios to versions below 0.34.0 or 1.20.0.
- Log and review any HTTP request configuration merges that occur in the presence of user-controlled JSON input parsed with Object.assign or recursive merge utilities.
- Correlate Node.js runtime crashes and 4xx/5xx spikes with recent input handling code paths to detect DoS attempts.
How to Mitigate CVE-2026-101909
Immediate Actions Required
- Upgrade Axios to version 0.34.0 (for the 0.x branch) or 1.20.0 (for the 1.x branch) across all applications and container images.
- Audit application code for prototype pollution sinks such as unsafe recursive merges, Object.assign with untrusted input, and lodash.set on user-controlled paths.
- Rebuild and redeploy Node.js services after updating lockfiles to ensure the patched version is loaded at runtime.
Patch Information
The maintainers released fixes in Axios v0.34.0 and Axios v1.20.0. Details are documented in GHSA-x97p-jq2g-jp4f and implemented via Pull Request #11141. The fix replaces prototype-chain lookups with own-property accessors and uses null-prototype objects for internal option containers.
Workarounds
- Freeze Object.prototype early during application bootstrap to prevent same-process prototype pollution primitives from succeeding.
- Avoid using toFormData with attacker-influenced configuration until upgrades are deployed.
- Sanitize and validate any input passed to recursive merge or property-set utilities that operate on plain JavaScript objects.
# Upgrade Axios to a patched version
npm install axios@^1.20.0
# or for the 0.x branch
npm install axios@0.34.0
# Verify installed version
npm ls axios
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.