Back

MEDIUM

Axios: Prototype pollution gadget in fetch adapter can alter outbound requests

Published Sep 28, 2026

Description

Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Request with sanitized resolvedOptions but then calls fetch with the original fetchOptions. A separate same-process prototype-pollution flaw populates Object.prototype.headers so fetchOptions.headers resolves through inheritance. The inherited fetchOptions.headers value overrides the sanitized Request headers through the second argument to fetch after Request construction. Attacker-controlled request headers can alter authorization, caching, metadata-service access, or application-specific behavior. This issue is fixed in version 1.20.0.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 28, 2026
Updated Sep 28, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Sep 28, 2026
NVD
Status Awaiting Analysis
Modified Sep 30, 2026
Red Hat
Severity Moderate
Public date Sep 28, 2026
GHSA-VH66-26GQ-Q6X8