Axios 是一个基于 Promise 的 HTTP 客户端,适用于浏览器和 Node.js 环境。在版本 1.16.1 至 1.20.0 之间,其用于处理 RFC 2397 数据 URL 的正则表达式存在缺陷,允许在媒体类型分隔符(逗号)的两侧包含斜杠字符(/)。当应用程序传入一个由攻击者构造的、包含大量斜杠字符但缺少逗号的数据 URL 时,JavaScript 正则表达式引擎会尝试多种分隔符放置方式,最终才拒绝该非法 URL。这一过程会导致同步过度回溯(synchronous excessive backtra
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101909 | 8.3 HIGH | Axios: Prototype Pollution Gadget in axios toFormData Options |
| CVE-2026-101901 | 8.2 HIGH | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial |
| CVE-2026-101906 | 8.2 HIGH | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi |
| CVE-2026-101905 | 7.6 HIGH | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher |
| CVE-2026-101898 | 7.0 HIGH | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101907 | 7.0 HIGH | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| CVE-2026-101900 | 6.9 MEDIUM | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| CVE-2026-101902 | 6.9 MEDIUM | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp |
| CVE-2026-101904 | 6.9 MEDIUM | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| CVE-2026-101908 | 6.9 MEDIUM | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
No comments yet