Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
Published Sep 28, 2026
7.6
HIGHCVSS 4.0
EPSS 0.29%
Description
Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.
Affected products
-
- Version >= 1.15.2, < 1.20.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Hardened Images
grafana12.4
Affected
Red Hat Hardened Images
grafana13.1
Affected
Red Hat Hardened Images
grafana13.2
Affected
Red Hat Hardened Images
jaeger
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | grafana12.4 | Affected | n/a |
| Red Hat Hardened Images | grafana13.1 | Affected | n/a |
| Red Hat Hardened Images | grafana13.2 | Affected | n/a |
| Red Hat Hardened Images | jaeger | Not affected | n/a |
axios
npm
Introduced 1.15.2 Fixed 1.20.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | axios | 1.15.2 | 1.20.0 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-101905 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2542584 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88382 Advisory
- https://github.com/advisories/GHSA-m8m8-qj5v-23w3 Advisory
- https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a x_refsource_MISC
- https://github.com/axios/axios/pull/11141 x_refsource_MISC
- https://github.com/axios/axios/releases/tag/v1.20.0 x_refsource_MISC
- https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3 exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-101905
- https://www.cve.org/CVERecord?id=CVE-2026-101905
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-101905 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2542584 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88382 | Advisory | |
| https://github.com/advisories/GHSA-m8m8-qj5v-23w3 | Advisory | |
| https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a | x_refsource_MISC | |
| https://github.com/axios/axios/pull/11141 | x_refsource_MISC | |
| https://github.com/axios/axios/releases/tag/v1.20.0 | x_refsource_MISC | |
| https://github.com/axios/axios/security/advisories/GHSA-m8m8-qj5v-23w3 | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-101905 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-101905 |
Change history (0)
No recorded changes yet.