CVE-2026-101902
— UNSCOREDpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-instance requests that omit an explicit method can read an inherited method value from Object.prototype. If another vulnerability in the same process pollutes Object.prototype.method, calls such as axios.request({ url }) and axios({ url }) can send a state-changing HTTP method instead of the expected default GET. Axios does not create the prototype pollution source. This is a read-side gadget in axios request dispatch. This issue is fixed in version 0.34.0 and 1.20.0.
Weaknesses
CWE-1321
Public exploit & PoC references
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
- https://github.com/axios/axios/pull/11141
- https://github.com/axios/axios/releases/tag/v0.34.0
- https://github.com/axios/axios/releases/tag/v1.20.0
- https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g
- https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g
All references
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
- https://github.com/axios/axios/pull/11141
- https://github.com/axios/axios/releases/tag/v0.34.0
- https://github.com/axios/axios/releases/tag/v1.20.0
- https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g
- https://github.com/axios/axios/security/advisories/GHSA-9fr6-4gfg-395g
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-101900PoC
- UNSCOREDCVE-2026-101904PoC
- UNSCOREDCVE-2026-101905PoC
- UNSCOREDCVE-2026-101908PoC
- UNSCOREDCVE-2026-101909PoC
- MEDIUMCVE-2026-14574PoC
- MEDIUMCVE-2026-61834PoC
- LOWCVE-2026-69200PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.