Axios 是一个面向浏览器和 Node.js 的基于 Promise 的 HTTP 客户端。在版本 1.7.0 至 1.20.0 之间,其 fetch 适配器会构造一个带有经过清理的 resolvedOptions 的 Request 对象,但随后仍使用原始的 fetchOptions 调用 fetch 函数。在同一进程中,存在一个独立的通过原型污染漏洞来篡改 Object.prototype.headers 的问题,导致 fetchOptions.headers 通过原型继承解析出值。在构造完 Request
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101909 | 8.3 HIGH | Axios: Prototype Pollution Gadget in axios toFormData Options |
| CVE-2026-101901 | 8.2 HIGH | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial |
| CVE-2026-101906 | 8.2 HIGH | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi |
| CVE-2026-101903 | 8.2 HIGH | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| CVE-2026-101905 | 7.6 HIGH | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher |
| CVE-2026-101898 | 7.0 HIGH | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101907 | 7.0 HIGH | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| CVE-2026-101900 | 6.9 MEDIUM | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| CVE-2026-101902 | 6.9 MEDIUM | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp |
| CVE-2026-101904 | 6.9 MEDIUM | Axios: Header Injection via Inherited headers After Minimal Interceptor |
No comments yet