Axios 是一个基于 Promise 的 HTTP 客户端,适用于浏览器和 Node.js 环境。从版本 1.17.0 到 1.20.0,其 适配器绕过了 的重定向策略。当 Axios 请求使用 适配器并将 设置为 0 时,若收到重定向响应,底层的 实现会跟随重定向,而不是将重定向响应原样返回。这导致即使禁用了重定向,重定向后的请求仍可能访问内部响应或触及具有状态更改的内部端点。该问题已在版本 1.20.0 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101909 | 8.3 HIGH | Axios: Prototype Pollution Gadget in axios toFormData Options |
| CVE-2026-101901 | 8.2 HIGH | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial |
| CVE-2026-101906 | 8.2 HIGH | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi |
| CVE-2026-101903 | 8.2 HIGH | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| CVE-2026-101905 | 7.6 HIGH | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher |
| CVE-2026-101898 | 7.0 HIGH | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101900 | 6.9 MEDIUM | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| CVE-2026-101902 | 6.9 MEDIUM | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp |
| CVE-2026-101904 | 6.9 MEDIUM | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| CVE-2026-101908 | 6.9 MEDIUM | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
No comments yet