Axios 是一个基于 Promise 的 HTTP 客户端,适用于浏览器和 Node.js 环境。在版本 1.12.0 至 1.20.0 期间, 在解析 FormData 请求头时,会读取继承自原型的 、 和 属性。此外,同一进程内的原型污染漏洞可导致注入一个数组或非纯类实例,其继承的属性使其行为类似于 FormData(纯对象已被阻止处理)。其中,继承的 函数可返回攻击者控制的请求头,这些请求头会被 合并到 fetch 适配器的请求中。攻击者控制的请求头可能篡改授权、缓存、元数据服务或特定应用相关的请求行为。该
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101909 | 8.3 HIGH | Axios: Prototype Pollution Gadget in axios toFormData Options |
| CVE-2026-101901 | 8.2 HIGH | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial |
| CVE-2026-101906 | 8.2 HIGH | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi |
| CVE-2026-101903 | 8.2 HIGH | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| CVE-2026-101905 | 7.6 HIGH | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher |
| CVE-2026-101898 | 7.0 HIGH | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101907 | 7.0 HIGH | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| CVE-2026-101902 | 6.9 MEDIUM | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp |
| CVE-2026-101904 | 6.9 MEDIUM | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| CVE-2026-101908 | 6.9 MEDIUM | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
No comments yet