Axios 是一个面向浏览器和 Node.js 的基于 Promise 的 HTTP 客户端。在版本 0.28.0 至 0.34.0 以及 1.15.1 至 1.20.0 之间, 函数会处理通过原型污染(prototype pollution)传入的继承序列化选项和访客函数属性。此外,在同一进程内还存在一个原型污染漏洞,可在对象序列化之前传入继承的 、 、 、 、 或 值。 这些被继承的选项会改变 的字段命名方式和数据解析逻辑; 设置可能导致请求失败; 对象的介入会更改值处理方式;而经过污染的 函数在攻击者已具备更
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101901 | 8.2 HIGH | Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initial |
| CVE-2026-101906 | 8.2 HIGH | Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redi |
| CVE-2026-101903 | 8.2 HIGH | Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS) |
| CVE-2026-101905 | 7.6 HIGH | Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inher |
| CVE-2026-101898 | 7.0 HIGH | Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls |
| CVE-2026-101907 | 7.0 HIGH | Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF |
| CVE-2026-101900 | 6.9 MEDIUM | Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders |
| CVE-2026-101902 | 6.9 MEDIUM | Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototyp |
| CVE-2026-101904 | 6.9 MEDIUM | Axios: Header Injection via Inherited headers After Minimal Interceptor |
| CVE-2026-101908 | 6.9 MEDIUM | Axios: Prototype pollution gadget in fetch adapter can alter outbound requests |
No comments yet