Back

HIGH

Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection

Published Sep 28, 2026

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib/adapters/http.js supplies request options without an own createConnection value. A separate same-process prototype-pollution flaw places a function on Object.prototype.createConnection. Node resolves and invokes the inherited createConnection socket factory, allowing the attacker-controlled function to select the transport endpoint. The attacker endpoint can receive request headers and bodies, including credentials, and return attacker-controlled responses while the URL appears legitimate. This issue is fixed in version 1.20.0.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 28, 2026
Updated Oct 1, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Awaiting Analysis
Modified Sep 30, 2026
Red Hat
Severity Important
Public date Sep 28, 2026
ENISA EUVD
Assigner GitHub_M
Published Sep 28, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-88382 GHSA-M8M8-QJ5V-23W3