CVE-2026-101908
— UNSCOREDpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0.
Weaknesses
CWE-1321
Public exploit & PoC references
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
- https://github.com/axios/axios/pull/11141
- https://github.com/axios/axios/releases/tag/v1.20.0
- https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8
- https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8
All references
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
- https://github.com/axios/axios/pull/11141
- https://github.com/axios/axios/releases/tag/v1.20.0
- https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8
- https://github.com/axios/axios/security/advisories/GHSA-vh66-26gq-q6x8
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-101900PoC
- UNSCOREDCVE-2026-101902PoC
- UNSCOREDCVE-2026-101904PoC
- UNSCOREDCVE-2026-101905PoC
- UNSCOREDCVE-2026-101909PoC
- MEDIUMCVE-2026-14574PoC
- MEDIUMCVE-2026-61834PoC
- LOWCVE-2026-69200PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.