CVE-2026-101900
Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag
CVSS
—
Sin CVSS
EPSS
0.5%
p44
KEV
—
Exploit Today
13
0-100
Publicado: 28 sept 2026 · Última mod.: 28 sept 2026 · CWE-74 · CWE-693 · CWE-1321
Sin historial EPSS suficiente todavía.
Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Symbol.toStringTag, append, and getHeaders properties while resolving FormData headers. A separate same-process prototype-pollution flaw supplies an array or non-plain class instance whose inherited properties make it appear FormData-like; plain objects are blocked. The inherited getHeaders function can return attacker-controlled headers that resolveConfig merges into a fetch adapter request. Attacker-controlled headers can alter authorization, cache, metadata-service, or application-specific request behavior. This issue is fixed in version 1.20.0.
- github.comhttps://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a
- github.comhttps://github.com/axios/axios/pull/11141
- github.comhttps://github.com/axios/axios/releases/tag/v1.20.0
- github.comhttps://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2
- github.comhttps://github.com/axios/axios/security/advisories/GHSA-4hqw-qxg8-jxx2